Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-327v-7xhm-qrxf

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Zarafa WebAccess 7.1.10 and WebApp 1.6 beta uses weak permissions (644) for config.php, which allows local users to obtain sensitive information by reading the PHP session files. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-0103.

Zarafa WebAccess 7.1.10 and WebApp 1.6 beta uses weak permissions (644) for config.php, which allows local users to obtain sensitive information by reading the PHP session files. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-0103.

EPSS

Процентиль: 30%
0.0037
Низкий

Дефекты

CWE-200

Связанные уязвимости

ubuntu
почти 12 лет назад

Zarafa WebAccess 7.1.10 and WebApp 1.6 beta uses weak permissions (644) for config.php, which allows local users to obtain sensitive information by reading the PHP session files. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-0103.

nvd
почти 12 лет назад

Zarafa WebAccess 7.1.10 and WebApp 1.6 beta uses weak permissions (644) for config.php, which allows local users to obtain sensitive information by reading the PHP session files. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-0103.

debian
почти 12 лет назад

Zarafa WebAccess 7.1.10 and WebApp 1.6 beta uses weak permissions (644 ...

EPSS

Процентиль: 30%
0.0037
Низкий

Дефекты

CWE-200