PHP-Survey 20000615 and earlier stores the global.inc file under the web root, which allows remote attackers to obtain sensitive information, including database credentials, if .inc files are not preprocessed by the server.
References
Link | Resource |
---|---|
http://archives.neohapsis.com/archives/bugtraq/2002-04/0383.html | Vendor Advisory |
http://www.iss.net/security_center/static/8950.php | Patch Vendor Advisory |
http://www.securityfocus.com/bid/4612 | Patch Vendor Advisory |
http://archives.neohapsis.com/archives/bugtraq/2002-04/0383.html | Vendor Advisory |
http://www.iss.net/security_center/static/8950.php | Patch Vendor Advisory |
http://www.securityfocus.com/bid/4612 | Patch Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
20 Nov 2024, 23:39
Type | Values Removed | Values Added |
---|---|---|
References | () http://archives.neohapsis.com/archives/bugtraq/2002-04/0383.html - Vendor Advisory | |
References | () http://www.iss.net/security_center/static/8950.php - Patch, Vendor Advisory | |
References | () http://www.securityfocus.com/bid/4612 - Patch, Vendor Advisory |
Information
Published : 2002-06-18 04:00
Updated : 2024-11-20 23:39
NVD link : CVE-2002-0614
Mitre link : CVE-2002-0614
CVE.ORG link : CVE-2002-0614
JSON object : View
Products Affected
php-survey
- php-survey
CWE