XLineSoft PHPRunner 3.1 stores the (1) database server name, (2) database names, (3) usernames, and (4) passwords in plaintext in %WINDIR%\PHPRunner.ini, which allows local users to obtain sensitive information by reading the file.
Link | Tags |
---|---|
http://secunia.com/advisories/22863 | third party advisory |
http://www.securityfocus.com/bid/21054 | vdb entry |
http://securitytracker.com/id?1017218 | vdb entry |
http://www.osvdb.org/30363 | vdb entry |
http://lostmon.blogspot.com/2006/11/phprunner-database-credentials.html |