PHP-Fusion before 7.02.06 stores backup files with predictable filenames in an unrestricted directory under the web document root, which might allow remote attackers to obtain sensitive information via a direct request to the backup file in administration/db_backups/.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2014-04-30 16:58
Updated : 2014-05-01 08:35
NVD link : CVE-2013-1807
Mitre link : CVE-2013-1807
JSON object : View
CWE
CWE-264
Permissions, Privileges, and Access Controls
Products Affected
php-fusion
- php-fusion