Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
PHP Webquest 2.6 allows remote attackers to retrieve database credentials via a direct request to admin/backup_phpwebquest.php, which leaks the credentials in an error message if a call to /usr/bin/mysqldump fails. NOTE: this might only be an issue in limited environments.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
PhpWebquest 'admin/backup_phpwebquest.php'导致信息泄露漏洞
Vulnerability Description
PHP Webquest 2.6允许远程攻击者通过对admin/backup_phpwebquest.php的直接请求重新取回数据库证件。如果对/usr/bin/mysqldump的命令失败的话,该请求会以一条错误的消息泄露证件。注意:这可能只能在受限环境下才会成为一个问题。
CVSS Information
N/A
Vulnerability Type
N/A