Efone Config.INC Information Disclosure Vulnerability
BID:18811
CVE-2006-3368 |Info
Efone Config.INC Information Disclosure Vulnerability
| Bugtraq ID: | 18811 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 04 2006 12:00AM |
| Updated: | Jul 04 2006 04:04PM |
| Credit: | DarkFig is credited with the discovery of this vulnerability. |
| Vulnerable: |
Efone Efone 20000723 |
| Not Vulnerable: | |
Discussion
Efone Config.INC Information Disclosure Vulnerability
Efone is prone to an information-disclosure vulnerability. This issue occurs because access controls on configuration files are not properly set.
An attacker can exploit this issue to retrieve potentially sensitive information. This may aid in further attacks.
It should be noted that this vulnerability exists only when the '.inc' file extension is not declared as a PHP suffix.
Efone is prone to an information-disclosure vulnerability. This issue occurs because access controls on configuration files are not properly set.
An attacker can exploit this issue to retrieve potentially sensitive information. This may aid in further attacks.
It should be noted that this vulnerability exists only when the '.inc' file extension is not declared as a PHP suffix.
Exploit / POC
Efone Config.INC Information Disclosure Vulnerability
This issue can be exploited through the use of a web client.
This issue can be exploited through the use of a web client.
Solution / Fix
Efone Config.INC Information Disclosure Vulnerability
Solution:
Currently we are not aware of any official vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]:[email protected].
Solution:
Currently we are not aware of any official vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]:[email protected].