TightAuction Config.INC Information Disclosure Vulnerability
BID:5850
Info
TightAuction Config.INC Information Disclosure Vulnerability
| Bugtraq ID: | 5850 |
| Class: | Configuration Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 02 2002 12:00AM |
| Updated: | Oct 02 2002 12:00AM |
| Credit: | Discovery of this issue is credited to "Frog Man" <[email protected]>. |
| Vulnerable: |
TightAuction TightAuction 3.0 |
| Not Vulnerable: | |
Discussion
TightAuction Config.INC Information Disclosure Vulnerability
TightAuction is prone to an information disclosure vulnerability. The configuration file (config.inc) contains sensitive information such as database authentication credentials. It is possible for remote attackers to retrieve this file via a web request, and since the file does not have the correct extension (.inc.php) the contents will be rendered in a web browser instead of interpreted.
TightAuction is prone to an information disclosure vulnerability. The configuration file (config.inc) contains sensitive information such as database authentication credentials. It is possible for remote attackers to retrieve this file via a web request, and since the file does not have the correct extension (.inc.php) the contents will be rendered in a web browser instead of interpreted.
Solution / Fix
TightAuction Config.INC Information Disclosure Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
TightAuction Config.INC Information Disclosure Vulnerability
References:
References: