PHP-Survey 20000615 and earlier stores the global.inc file under the web root, which allows remote attackers to obtain sensitive information, including database credentials, if .inc files are not preprocessed by the server.
References
Link | Resource |
---|---|
http://archives.neohapsis.com/archives/bugtraq/2002-04/0383.html | Vendor Advisory |
http://www.securityfocus.com/bid/4612 | Patch Vendor Advisory |
http://www.iss.net/security_center/static/8950.php | Patch Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2002-06-17 21:00
Updated : 2008-09-05 13:28
NVD link : CVE-2002-0614
Mitre link : CVE-2002-0614
JSON object : View
CWE
Products Affected
php-survey
- php-survey