eFileMan 7.1.0.87-88 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain unspecified user information via a direct request for cgi-bin/efileman/efileman_config.pm.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Efileman | Efileman | 7.1.0.87_88 (including) | 7.1.0.87_88 (including) |