Security Advisory

CVE-2000-1100

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2000-12-19 05:00:00
Last updated 2024-08-08 05:45:37
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

The default configuration for PostACI webmail system installs the /includes/global.inc configuration file within the web root, which allows remote attackers to read sensitive information such as database usernames and passwords via a direct HTTP GET request.