Quicksilver Forums before 1.4.1 allows remote attackers to obtain sensitive information by causing unspecified connection errors, which reveals the database password in the resulting error message.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://secunia.com/advisories/26998 | third party advisory vendor advisory |
http://www.securityfocus.com/bid/25887 | vdb entry |
http://forums.quicksilverforums.com/index.php?a=topic&t=1332 | patch |
https://exchange.xforce.ibmcloud.com/vulnerabilities/36891 | vdb entry |