Livre Dor' Information Disclosure Vulnerability
BID:4629
Info
Livre Dor' Information Disclosure Vulnerability
| Bugtraq ID: | 4629 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 27 2002 12:00AM |
| Updated: | Apr 27 2002 12:00AM |
| Credit: | Discovered by frog frog <[email protected]>. |
| Vulnerable: |
Livre Dor' Livre Dor' 1.1 |
| Not Vulnerable: | |
Discussion
Livre Dor' Information Disclosure Vulnerability
Livre Dor is subject to an information disclosure issue. Reportedly, config.inc and connexion.inc are both world readable and both contain highly sensitive data.
Obtaining the information contained within either file, could result in the attacker launching further attacks against the host.
Livre Dor is subject to an information disclosure issue. Reportedly, config.inc and connexion.inc are both world readable and both contain highly sensitive data.
Obtaining the information contained within either file, could result in the attacker launching further attacks against the host.
Exploit / POC
Livre Dor' Information Disclosure Vulnerability
No exploit code is required.
No exploit code is required.
Solution / Fix
Livre Dor' Information Disclosure Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Livre Dor' Information Disclosure Vulnerability
References:
References:
- Livre Dor' Homepage (COMUWEB )
- Security holes in 11 products... (frog frog
)