CVE
- Id
- 2667
- CVE No.
- CVE-2000-1100
- Status
- Candidate
- Description
- The default configuration for PostACI webmail system installs the /includes/global.inc configuration file within the web root, which allows remote attackers to read sensitive information such as database usernames and passwords via a direct HTTP GET request.
- Phase
- Proposed (20001219)
- Votes
- ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(2) Cole, Wall
- Comments
- Frech> XF:postaci-webmail-reveal-passwords(5612)