ezRADIUS 0.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain credentials via a direct request for (1) config.ini or (2) database.ini. NOTE: some of these details are obtained from third party information.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/41767 | vdb entry |
http://sourceforge.net/forum/forum.php?forum_id=809832 | |
http://sourceforge.net/project/shownotes.php?release_id=591272&group_id=221332 | |
http://www.osvdb.org/44399 | vdb entry |
http://secunia.com/advisories/29769 | third party advisory vendor advisory |