Vulnerabilities > CVE-2006-2443 - Information Disclosure vulnerability in Knowledgetree 2.0.7

047910
CVSS 4.6 - MEDIUM
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
local
low complexity
knowledgetree

Summary

The Debian package of knowledgetree 2.0.7 creates environment.php with world-readable permissions, which allows local users to obtain sensitive information such as the username and password for the KnowledgeTree database.

Vulnerable Configurations

Part Description Count
Application
Knowledgetree
1