@Mail WebMail Client in AtMail Open-Source 1.04 and earlier allows remote attackers to obtain configuration information via a direct request to install/info.php, which calls the phpinfo function.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://en.securitylab.ru/lab/PT-2011-48 | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/74282 | vdb entry |
http://www.kb.cert.org/vuls/id/743555 | third party advisory us government resource |
http://secunia.com/advisories/47012 | third party advisory |