CVE

Id
72745  
CVE No.
CVE-2014-5447  
Status
Candidate  
Description
Zarafa WebAccess 7.1.10 and WebApp 1.6 beta uses weak permissions (644) for config.php, which allows local users to obtain sensitive information by reading the PHP session files. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-0103.  
Phase
Assigned (20140825)  
Votes
None (candidate not yet proposed)  
Comments