TightAuction 3.0 stores config.inc under the web document root with insufficient access control, which allows remote attackers to obtain the database username and password.
References
Configurations
History
20 Nov 2024, 23:42
Type | Values Removed | Values Added |
---|---|---|
References | () http://archives.neohapsis.com/archives/bugtraq/2002-10/0016.html - Exploit | |
References | () http://www.iss.net/security_center/static/10310.php - | |
References | () http://www.securityfocus.com/bid/5850 - Exploit |
Information
Published : 2002-12-31 05:00
Updated : 2024-11-20 23:42
NVD link : CVE-2002-1886
Mitre link : CVE-2002-1886
CVE.ORG link : CVE-2002-1886
JSON object : View
Products Affected
tightauction
- tightauction
CWE