CVE-2007-1597 Information
Feb 14, 2021
cve
Description
Unclassified NewsBoard 1.6.3 stores sensitive information under the web root with insufficient access control which allows remote attackers to obtain (1) the board log via a direct request for logs/board-YYYY-MM-DD.log (2) the mail and private message (PM) log via a direct request for logs/email-YY-MM-DD-HH-MM-SS.log (3) the SQL error message log via a direct request for logs/error-YY-MM.log and (4) the IP log via a direct request for logs/ip.log.
Reference
http://osvdb.org/35201 http://www.securityfocus.com/archive/1/463186/100/0/threaded https://exchange.xforce.ibmcloud.com/vulnerabilities/33150
Share on: