First published: Wed Apr 30 2014(Updated: )
PHP-Fusion before 7.02.06 stores backup files with predictable filenames in an unrestricted directory under the web document root, which might allow remote attackers to obtain sensitive information via a direct request to the backup file in administration/db_backups/.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Php-fusion Php-fusion | <=7.02.05 | |
Php-fusion Php-fusion | =7.02.01 | |
Php-fusion Php-fusion | =7.02.02 | |
Php-fusion Php-fusion | =7.02.03 | |
Php-fusion Php-fusion | =7.02.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.