Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Ryan Fox

#34592of 53,630
7.5Total CVSS
Vulnerabilities · 1
PT-2003-2328
7.5
2003-12-31
Weberp · Weberp · CVE-2003-1383
**Name of the Vulnerable Software and Affected Versions** WEB-ERP versions 0.1.4 and earlier **Description** The issue allows remote attackers to obtain sensitive information via an HTTP request for the `logicworks.ini` file, which contains the MySQL database `username` and `password`. **Recommendations** For versions 0.1.4 and earlier, restrict access to the `logicworks.ini` file to prevent unauthorized disclosure of database credentials.