Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

David B Harris

#50621of 53,632
4.6Total CVSS
Vulnerabilities · 1
PT-2006-3404
4.6
2006-05-18
Knowledgetree · Knowledgetree · CVE-2006-2443
**Name of the Vulnerable Software and Affected Versions** knowledgetree version 2.0.7 **Description** The issue allows local users to obtain sensitive information, including the username and password for the KnowledgeTree database, due to the Debian package of knowledgetree creating the environment.php file with world-readable permissions. **Recommendations** For knowledgetree version 2.0.7, consider changing the permissions of the environment.php file to prevent world-readable access, and restrict access to sensitive database credentials.