CVE-2009-4961: Infoleak
Published Jul 27, 2010
·Updated
Lanai Core 0.6 allows remote attackers to obtain configuration information via a direct request to info.php, which calls the phpinfo function.
Affected Software
1 affected component
Lanai-core Lanai-core=0.6
Event History
Jul 27, 2010
CVE Published
via MITRE·06:39 PM
Data Sourced
via MITRE·06:39 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2009-4961?
CVE-2009-4961 is considered a high severity vulnerability due to the risk of exposing sensitive configuration information.
2
How do I fix CVE-2009-4961?
To fix CVE-2009-4961, you should restrict access to the info.php file or remove it from the server.
3
What type of vulnerability is CVE-2009-4961?
CVE-2009-4961 is a remote information disclosure vulnerability.
4
What version of Lanai Core is affected by CVE-2009-4961?
CVE-2009-4961 specifically affects Lanai Core version 0.6.
5
What could an attacker achieve with CVE-2009-4961?
An attacker exploiting CVE-2009-4961 could obtain sensitive configuration data that may assist in further attacks.