Vulnerabilities > CVE-2006-5956 - Local Information Disclosure vulnerability in Xlinesoft PHPrunner 3.1

047910
CVSS 2.1 - LOW
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
local
low complexity
xlinesoft

Summary

XLineSoft PHPRunner 3.1 stores the (1) database server name, (2) database names, (3) usernames, and (4) passwords in plaintext in %WINDIR%\PHPRunner.ini, which allows local users to obtain sensitive information by reading the file.

Vulnerable Configurations

Part Description Count
Application
Xlinesoft
1