Secunia Logo
 
CVE Reference: CVE-2004-1724
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2004-1724

Description:
The ReadMe First.txt file in PHP-Fusion 4.0 instructs users to set the permissions on the fusion_admin/db_backups directory to world read/write/execute (777), which allows remote attackers to download or view database backups, which have easily guessable filenames and contain the administrator username and password.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/17037

SAID
  Secunia Advisory: SA12336

BUGTRAQ
  http://marc.theaimsgroup.com/?l=bugtraq&m=109285292901685&w=2

BID
  10974


Return to the previous page.