First published: Thu Jan 11 2001(Updated: )
Basilix Webmail 0.9.7beta, and possibly other versions, stores *.class and *.inc files under the document root and does not restrict access, which could allows remote attackers to obtain sensitive information such as MySQL passwords and usernames from the mysql.class file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Basilix Basilix Webmail | =0.9.7_beta |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.