Killer Protection 1.0 stores the vars.inc include file under the web root with insufficient access control, which allows remote attackers to obtain user names and passwords and log in using protection.php.
References
Configurations
Information
Published : 2002-12-30 21:00
Updated : 2008-09-05 13:32
NVD link : CVE-2002-2335
Mitre link : CVE-2002-2335
JSON object : View
CWE
CWE-16
Configuration
Products Affected
john_drake
- killer_protection