Kamikaze-QSCM Config.INC Information Disclosure Vulnerability
BID:18816
CVE-2006-3369 |Info
Kamikaze-QSCM Config.INC Information Disclosure Vulnerability
| Bugtraq ID: | 18816 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 04 2006 12:00AM |
| Updated: | Jul 05 2006 05:34PM |
| Credit: | DarkFig is credited with the discovery of this vulnerability. |
| Vulnerable: |
Iduprey Kamikaze-qscm 0.2 |
| Not Vulnerable: | |
Discussion
Kamikaze-QSCM Config.INC Information Disclosure Vulnerability
Kamikaze-qscm is prone to an information-disclosure vulnerability. This issue occurs because access controls on configuration files are not properly set.
An attacker can exploit this issue to retrieve potentially sensitive information. This may aid in further attacks.
Note that this vulnerability occurs only when the '.inc' file extension is not declared as a PHP suffix.
Kamikaze-qscm is prone to an information-disclosure vulnerability. This issue occurs because access controls on configuration files are not properly set.
An attacker can exploit this issue to retrieve potentially sensitive information. This may aid in further attacks.
Note that this vulnerability occurs only when the '.inc' file extension is not declared as a PHP suffix.
Exploit / POC
Kamikaze-QSCM Config.INC Information Disclosure Vulnerability
This issue can be exploited through a web client.
This issue can be exploited through a web client.
Solution / Fix
Kamikaze-QSCM Config.INC Information Disclosure Vulnerability
Solution:
Currently we are not aware of any official vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]:[email protected].
Solution:
Currently we are not aware of any official vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]:[email protected].
References
Kamikaze-QSCM Config.INC Information Disclosure Vulnerability
References:
References:
- Kamikaze-qscm Home Page (iduprey)