CVE

Id
10824  
CVE No.
CVE-2004-2398  
Status
Candidate  
Description
Netenberg Fantastico De Luxe 2.8 uses database file names that contain the associated usernames, which allows local users to determine valid usernames and conduct brute force attacks by reading the file names from /var/lib/mysql, which is assigned world-readable permissions by cPanel 9.3.0 R5.  
Phase
Assigned (20050817)  
Votes
None (candidate not yet proposed)  
Comments