2532designs 2532|Gigs 1.2.2 and earlier allows remote attackers to trigger a backup and obtain sensitive information via a direct request to backup.php, which creates backup.sql under the web root with insufficient access control.
Name | Vendor | Start Version | End Version |
---|---|---|---|
2532gigs | 2532gigs | * | 1.2.2 (including) |
2532gigs | 2532gigs | 1.2.1 (including) | 1.2.1 (including) |