CVE-2007-5129 Information
Description
SimpGB 1.46.02 stores sensitive information under the web root with insufficient access control which allows remote attackers to (1) obtain sensitive configuration information via a direct request for admin/cfginfo.php; and (2) download arbitrary .inc files via a direct request as demonstrated by admin/includes/dbtables.inc.
Reference
http://forum.boesch-it.de/viewtopic.php?t=2790 http://osvdb.org/40612 http://osvdb.org/40613 http://secunia.com/advisories/26974 http://www.netvigilance.com/advisory0065 http://www.netvigilance.com/advisory0066 http://www.securityfocus.com/archive/1/480590/100/0/threaded http://www.securityfocus.com/archive/1/480592/100/0/threaded https://exchange.xforce.ibmcloud.com/vulnerabilities/36776 https://exchange.xforce.ibmcloud.com/vulnerabilities/36777
Share on: