RSS   Vulnerabilities for 'Phpdirector'   RSS

2007-07-03
 
CVE-2007-3530

CWE-Other
 

 
PHPDirector 0.21 and earlier stores the admin account name and password in config.php, which allows local users to gain privileges by reading this file.

 
 
CVE-2007-3529

CWE-Other
 

 
videos.php in PHPDirector 0.21 and earlier allows remote attackers to obtain sensitive information via an empty value of the id[] parameter, which reveals the path in an error message.

 


Copyright 2024, cxsecurity.com

 

Back to Top