Vulnerabilities > CVE-2006-4772 - Unspecified vulnerability in Hotplug CMS Hotplug CMS
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
HotPlug CMS stores sensitive information under the web root with insufficient access control, which allows remote attackers to read the admin password and database credentials via a direct request for includes/class/config.inc.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |