CVE Vulnerabilities

CVE-2013-1807

Published: Apr 30, 2014 | Modified: May 01, 2014
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

PHP-Fusion before 7.02.06 stores backup files with predictable filenames in an unrestricted directory under the web document root, which might allow remote attackers to obtain sensitive information via a direct request to the backup file in administration/db_backups/.

Affected Software

Name Vendor Start Version End Version
Php-fusion Php-fusion * 7.02.05 (including)
Php-fusion Php-fusion 7.02.01 (including) 7.02.01 (including)
Php-fusion Php-fusion 7.02.02 (including) 7.02.02 (including)
Php-fusion Php-fusion 7.02.03 (including) 7.02.03 (including)
Php-fusion Php-fusion 7.02.04 (including) 7.02.04 (including)

References