Vulnerabilities > CVE-2007-0880 - Information Disclosure vulnerability in Capital Request Forms

047910
CVSS 7.8 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
NONE
Availability impact
NONE
network
low complexity
capital-request-forms

Summary

Capital Request Forms stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain database credentials via a direct request for inc/common_db.inc.

Vulnerable Configurations

Part Description Count
Application
Capital_Request_Forms
1