Total vulnerabilities in the database
PHP-Fusion before 7.02.06 stores backup files with predictable filenames in an unrestricted directory under the web document root, which might allow remote attackers to obtain sensitive information via a direct request to the backup file in administration/db_backups/.
Software | From | Fixed in |
---|---|---|
php-fusion / php-fusion | - | 7.02.05.x |
php-fusion / php-fusion | 7.02.03 | 7.02.03.x |
php-fusion / php-fusion | 7.02.01 | 7.02.01.x |
php-fusion / php-fusion | 7.02.02 | 7.02.02.x |
php-fusion / php-fusion | 7.02.04 | 7.02.04.x |