|
Family: CGI abuses --> Category: attack
GTcatalog password disclosure Vulnerability Scan
Vulnerability Scan Summary Searches for the existence of password.inc
Detailed Explanation for this Vulnerability Test
It is possible to obtain the password of the remote GTcatalog package
by requestingthe file password.inc
A possible hacker may use this flaw to inject arbitrary code in the remote
host and gain a shell with the rights of the web server.
Solution : See http://www.phpsecure.org or contact the vendor for a patch
Threat Level: High
Click HERE for more information and discussions on this network vulnerability scan.
|