CVE-2013-1807
30.04.2014, 23:58
PHP-Fusion before 7.02.06 stores backup files with predictable filenames in an unrestricted directory under the web document root, which might allow remote attackers to obtain sensitive information via a direct request to the backup file in administration/db_backups/.Enginsight
Vendor | Product | Version |
---|---|---|
php-fusion | php-fusion | 𝑥 ≤ 7.02.05 |
php-fusion | php-fusion | 7.02.01 |
php-fusion | php-fusion | 7.02.02 |
php-fusion | php-fusion | 7.02.03 |
php-fusion | php-fusion | 7.02.04 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References