vendor:
PHP-Fusion
by:
Anonymous
5.5
CVSS
MEDIUM
Information Disclosure
200
CWE
Product Name: PHP-Fusion
Affected Version From: 4
Affected Version To: Unknown
Patch Exists: NO
Related CWE:
CPE: a:php-fusion:php-fusion
Platforms Tested:
2004
PHP-Fusion Database Backup Information Disclosure
An anonymous remote attacker can download a complete database backup from the server without authentication, potentially exposing user information and password hashes. The backup file includes the MD5 password hashes, which can be used for further attacks against the application. The issue affects PHP-Fusion version 4.00 and possibly other versions.
Mitigation:
Configure the web server to restrict access to sensitive files.