PT-2003-2328 · Weberp · Weberp

Ryan Fox

·

Published

2003-12-31

·

Updated

2017-07-29

·

CVE-2003-1383

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions WEB-ERP versions 0.1.4 and earlier
Description The issue allows remote attackers to obtain sensitive information via an HTTP request for the logicworks.ini file, which contains the MySQL database username and password.
Recommendations For versions 0.1.4 and earlier, restrict access to the logicworks.ini file to prevent unauthorized disclosure of database credentials.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2003-1383

Affected Products

Weberp