paFAQ 1.0 Beta 4 allows remote attackers to obtain sensitive information via a direct request to admin/backup.php, which contains a backup of the database including usernames and passwords.
Link | Tags |
---|---|
http://marc.info/?l=bugtraq&m=111928841328681&w=2 | mailing list |
http://www.gulftech.org/?node=research&article_id=00083-06202005 | exploit |