CVE-2007-3556 Information

Description

Liesbeth base CMS stores sensitive information under the web root with insufficient access control which allows remote attackers to download an include file containing account credentials via a direct request for config.inc.

Reference

http://osvdb.org/45744 http://securityreason.com/securityalert/2857 http://securityvulns.ru/Rdocument392.html http://www.securityfocus.com/archive/1/472727/100/0/threaded http://www.securityfocus.com/bid/24749 https://exchange.xforce.ibmcloud.com/vulnerabilities/35243

Share on: