Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
amaroK Web Frontend 1.3 stores the globals.inc file under the web root without a .php extension and insufficient access control, which allows remote attackers to obtain the database username and password via a direct request to the file.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
amaroK Web Frontend 'globals.inc'敏感信息泄露漏洞
Vulnerability Description
amaroK Web Frontend 1.3对web根目录下存储的globals.inc文件未加.php扩展名,且访问控制不足,远程攻击者可利用此漏洞借助对该文件的直接请求获得数据库用户名和密码。
CVSS Information
N/A
Vulnerability Type
N/A