First published: Thu Sep 27 2007(Updated: )
SimpGB 1.46.02 stores sensitive information under the web root with insufficient access control, which allows remote attackers to (1) obtain sensitive configuration information via a direct request for admin/cfginfo.php; and (2) download arbitrary .inc files via a direct request, as demonstrated by admin/includes/dbtables.inc.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Boesch-it Simpgb | =1.46.02 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.