Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4pw5-9j6v-6728

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

setting.php in Innovative CMS (ICMS, formerly Imoel-CMS) contains username and password information in cleartext, which might allow attackers to obtain this information via a direct request to setting.php. NOTE: on a properly configured web server, it would be expected that a .php file would be processed before content is returned to the user, so this might not be a vulnerability.

setting.php in Innovative CMS (ICMS, formerly Imoel-CMS) contains username and password information in cleartext, which might allow attackers to obtain this information via a direct request to setting.php. NOTE: on a properly configured web server, it would be expected that a .php file would be processed before content is returned to the user, so this might not be a vulnerability.

EPSS

Процентиль: 63%
0.00446
Низкий

Связанные уязвимости

nvd
около 20 лет назад

setting.php in Innovative CMS (ICMS, formerly Imoel-CMS) contains username and password information in cleartext, which might allow attackers to obtain this information via a direct request to setting.php. NOTE: on a properly configured web server, it would be expected that a .php file would be processed before content is returned to the user, so this might not be a vulnerability.

EPSS

Процентиль: 63%
0.00446
Низкий