First published: Fri Dec 31 2004(Updated: )
Netenberg Fantastico De Luxe 2.8 uses database file names that contain the associated usernames, which allows local users to determine valid usernames and conduct brute force attacks by reading the file names from /var/lib/mysql, which is assigned world-readable permissions by cPanel 9.3.0 R5.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Netenberg Fantastico De Luxe | =2.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.