TightAuction 3.0 stores config.inc under the web document root with insufficient access control, which allows remote attackers to obtain the database username and password.
Affected Software
Name |
Vendor |
Start Version |
End Version |
Tightauction |
Tightauction |
3.0 (including) |
3.0 (including) |
References