Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The setup script in Domain Technologie Control (DTC) before 0.34.1 uses world-readable permissions for /etc/apache2/apache2.conf, which allows local users to obtain the dtcdaemons MySQL password by reading the file.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
GPLHost Domain Technologie Control 权限许可和访问控制漏洞
Vulnerability Description
Domain Technologie Control(DTC)是美国GPLHost公司赞助的一个基于Web的主机控制面板,它支持使用一个Web图形用户界面来管理所有主机服务,例如为域用户创建子域、邮件和FTP帐号等。 DTC 0.32.11及之前版本中的setup脚本中存在安全漏洞,该漏洞源于程序对/etc/apache2/apache2.conf文件使用全局可读权限。本地攻击者可通过读取文件利用该漏洞获取dtcdaemons MySQL密码。
CVSS Information
N/A
Vulnerability Type
N/A