DotBr 0.1 stores config.inc with insufficient access control under the web document root, which allows remote attackers to obtain sensitive information such as SQL usernames and passwords.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2007-10-20T10:00:00

Updated: 2024-08-08T02:28:02.631Z

Reserved: 2007-10-19T00:00:00

Link: CVE-2003-1404

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2003-12-31T05:00:00.000

Modified: 2024-11-20T23:47:03.683

Link: CVE-2003-1404

cve-icon Redhat

No data.