Beveiligingsadvies

CVE-2007-1597

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2007-03-22 23:00:00
Laatst bijgewerkt 2024-08-07 12:59:08
Toegewezen door mitre
CVSS-score geen score
Status PUBLISHED

Beschrijving

Unclassified NewsBoard 1.6.3 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain (1) the board log via a direct request for logs/board-YYYY-MM-DD.log, (2) the mail and private message (PM) log via a direct request for logs/email-YY-MM-DD-HH-MM-SS.log, (3) the SQL error message log via a direct request for logs/error-YY-MM.log, and (4) the IP log via a direct request for logs/ip.log.