CVE

Id
13281  
CVE No.
CVE-2005-2075  
Status
Candidate  
Description
PHP-Fusion 5.0 and 6.0 stores the database file with a predictable filename under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request to the filename in the administration/db_backups directory in PHP-Fusion 6.0 or the fusion_admin/db_backups directory in 5.0.  
Phase
Assigned (20050629)  
Votes
None (candidate not yet proposed)  
Comments