Web-ERP Configuration File Remote Access Vulnerability
BID:6996
Info
Web-ERP Configuration File Remote Access Vulnerability
| Bugtraq ID: | 6996 |
| Class: | Configuration Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 01 2003 12:00AM |
| Updated: | Mar 01 2003 12:00AM |
| Credit: | Discovery credited to "Ryan Fox" <[email protected]>. |
| Vulnerable: |
Web-ERP Web-ERP 0.1.4 |
| Not Vulnerable: |
Web-ERP Web-ERP 0.1.5 |
Discussion
Web-ERP Configuration File Remote Access Vulnerability
It has been reported that Web-ERP does not sufficiently restrict access to it's configuration information. Because of this, an attacker may be able to remotely access Web-ERP information, and potentially gain access to information that is sensitive in nature.
It has been reported that Web-ERP does not sufficiently restrict access to it's configuration information. Because of this, an attacker may be able to remotely access Web-ERP information, and potentially gain access to information that is sensitive in nature.
Exploit / POC
Web-ERP Configuration File Remote Access Vulnerability
This vulnerability may be exploited with a web browser.
This vulnerability may be exploited with a web browser.
Solution / Fix
Web-ERP Configuration File Remote Access Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Web-ERP Configuration File Remote Access Vulnerability
References:
References:
- Web-ERP Project Page (Web-ERP)
- web-erp 0.1.4 database access vulnerability ("Ryan Fox"
)