Easy File Sharing (EFS) Web Server 1.2 stores the (1) option.ini (aka options.ini) file and (2) log directory under the web root with insufficient access control, which allows remote attackers to obtain sensitive information including an SMTP account username and password hash, the server configuration, and server log files.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2006-03-19T23:00:00Z

Updated: 2024-09-16T20:03:22.797Z

Reserved: 2006-03-19T00:00:00Z

Link: CVE-2003-1297

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2003-12-31T05:00:00.000

Modified: 2008-09-05T20:36:34.057

Link: CVE-2003-1297

cve-icon Redhat

No data.