amaroK Web Frontend 1.3 stores the globals.inc file under the web root without a .php extension and insufficient access control, which allows remote attackers to obtain the database username and password via a direct request to the file.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Web_frontend | Amarok | 1.3 (including) | 1.3 (including) |