PHP-Fusion before 7.02.06 stores backup files with predictable filenames in an unrestricted directory under the web document root, which might allow remote attackers to obtain sensitive information via a direct request to the backup file in administration/db_backups/.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Php-fusion | Php-fusion | * | 7.02.05 (including) |
Php-fusion | Php-fusion | 7.02.01 (including) | 7.02.01 (including) |
Php-fusion | Php-fusion | 7.02.02 (including) | 7.02.02 (including) |
Php-fusion | Php-fusion | 7.02.03 (including) | 7.02.03 (including) |
Php-fusion | Php-fusion | 7.02.04 (including) | 7.02.04 (including) |