PT-2006-6621 · Xlinesoft · Phprunner

Lostmon

·

Published

2006-11-17

·

Updated

2008-09-05

·

CVE-2006-5956

CVSS v2.0

2.1

Low

VectorAV:L/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions XLineSoft PHPRunner version 3.1
Description The issue allows local users to obtain sensitive information, including database server names, database names, usernames, and passwords, which are stored in plaintext in the %WINDIR%PHPRunner.ini file.
Recommendations For XLineSoft PHPRunner version 3.1, consider restricting access to the PHPRunner.ini file to minimize the risk of exploitation. As a temporary workaround, limit local user access to sensitive information stored in the file until a more secure method of storing this data is implemented.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-5956

Affected Products

Phprunner