PT-2002-2608 · Tightauction · Tightauction

Publicado

2002-12-31

·

Atualizado

2008-09-05

·

CVE-2002-1886

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions TightAuction version 3.0
Description The issue allows remote attackers to obtain the database username and password due to insufficient access control of the config.inc file, which is stored under the web document root.
Recommendations For TightAuction version 3.0, consider moving the config.inc file outside of the web document root or implementing proper access controls to restrict unauthorized access to this file. As a temporary workaround, restrict access to the config.inc file to minimize the risk of exploitation.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2002-1886

Produtos afetados

Tightauction