DotBr 0.1 stores config.inc with insufficient access control under the web document root, which allows remote attackers to obtain sensitive information such as SQL usernames and passwords.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/6865 | vdb entry |
http://www.osvdb.org/5092 | vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/11354 | vdb entry |
http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0070.html | mailing list |