Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The default configuration for PostACI webmail system installs the /includes/global.inc configuration file within the web root, which allows remote attackers to read sensitive information such as database usernames and passwords via a direct HTTP GET request.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Trlinux Postaci Webmail 密码泄漏漏洞
Vulnerability Description
PostACI web邮件系统默认配置安装web根目录的/includes/global.inc配置文件。远程攻击者可以借助直接HTTP GET请求读取如数据库用户名和密码的敏感信息。
CVSS Information
N/A
Vulnerability Type
N/A