W-Agora (Web-Agora) 4.2.1, when register_globals is enabled, stores globals.inc under the web document root with insufficient access control, which allows remote attackers to obtain application path information via a direct request.
References
Configurations
Information
Published : 2007-03-20 13:19
Updated : 2018-10-16 09:33
NVD link : CVE-2007-0607
Mitre link : CVE-2007-0607
JSON object : View
CWE
Products Affected
w-agora
- w-agora