Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-43r6-r8w4-qp6c

Опубликовано: 30 апр. 2022
Источник: github
Github: Не прошло ревью

Описание

Basilix Webmail 0.9.7beta, and possibly other versions, stores *.class and *.inc files under the document root and does not restrict access, which could allows remote attackers to obtain sensitive information such as MySQL passwords and usernames from the mysql.class file.

Basilix Webmail 0.9.7beta, and possibly other versions, stores *.class and *.inc files under the document root and does not restrict access, which could allows remote attackers to obtain sensitive information such as MySQL passwords and usernames from the mysql.class file.

EPSS

Процентиль: 92%
0.07909
Низкий

Связанные уязвимости

nvd
больше 24 лет назад

Basilix Webmail 0.9.7beta, and possibly other versions, stores *.class and *.inc files under the document root and does not restrict access, which could allows remote attackers to obtain sensitive information such as MySQL passwords and usernames from the mysql.class file.

EPSS

Процентиль: 92%
0.07909
Низкий