Liesbeth base CMS stores sensitive information under the web root with insufficient access control, which allows remote attackers to download an include file containing account credentials via a direct request for config.inc.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/35243 | vdb entry |
http://osvdb.org/45744 | vdb entry |
http://securityvulns.ru/Rdocument392.html | |
http://www.securityfocus.com/archive/1/472727/100/0/threaded | mailing list |
http://securityreason.com/securityalert/2857 | third party advisory |
http://www.securityfocus.com/bid/24749 | vdb entry |