PT-2010-3677 · Prewikka · Prewikka
Robert Buchholz
·
Published
2010-06-07
·
Updated
2017-08-17
·
CVE-2010-2058
CVSS v2.0
2.1
Low
| Vector | AV:L/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Prewikka version 0.9.14
Description
The issue allows local users to obtain the SQL database password due to the world-readable permissions of the prewikka.conf file installed by setup.py.
Recommendations
For Prewikka version 0.9.14, consider changing the permissions of the prewikka.conf file to restrict access and prevent unauthorized users from reading the SQL database password.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Prewikka