Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-327v-7xhm-qrxf

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Zarafa WebAccess 7.1.10 and WebApp 1.6 beta uses weak permissions (644) for config.php, which allows local users to obtain sensitive information by reading the PHP session files. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-0103.

Zarafa WebAccess 7.1.10 and WebApp 1.6 beta uses weak permissions (644) for config.php, which allows local users to obtain sensitive information by reading the PHP session files. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-0103.

EPSS

Процентиль: 15%
0.00048
Низкий

Дефекты

CWE-200

Связанные уязвимости

ubuntu
больше 11 лет назад

Zarafa WebAccess 7.1.10 and WebApp 1.6 beta uses weak permissions (644) for config.php, which allows local users to obtain sensitive information by reading the PHP session files. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-0103.

nvd
больше 11 лет назад

Zarafa WebAccess 7.1.10 and WebApp 1.6 beta uses weak permissions (644) for config.php, which allows local users to obtain sensitive information by reading the PHP session files. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-0103.

debian
больше 11 лет назад

Zarafa WebAccess 7.1.10 and WebApp 1.6 beta uses weak permissions (644 ...

EPSS

Процентиль: 15%
0.00048
Низкий

Дефекты

CWE-200