CVE-2007-5129
CVE-2007-5129
SimpGB 1.46.02 stores sensitive information under the web root with insufficient access control, which allows remote attackers to (1) obtain sensitive configuration information via a direct request for admin/cfginfo.php; and (2) download arbitrary .inc files via a direct request, as demonstrated by admin/includes/dbtables.inc.
Produtos afetados
n/a · n/aQuer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →Referências
http://forum.boesch-it.de/viewtopic.php?t=2790http://osvdb.org/40612http://osvdb.org/40613http://secunia.com/advisories/26974https://exchange.xforce.ibmcloud.com/vulnerabilities/36776https://exchange.xforce.ibmcloud.com/vulnerabilities/36777http://www.netvigilance.com/advisory0065http://www.netvigilance.com/advisory0066http://www.securityfocus.com/archive/1/480590/100/0/threadedhttp://www.securityfocus.com/archive/1/480592/100/0/threaded