Total vulnerabilities in the database
LimeSurvey 2.6.x before 2.6.7, 2.7x.x before 2.73.1, and 3.x before 3.4.2 mishandles application/controller/InstallerController.php after installation, which allows remote attackers to access the configuration file.
Software | From | Fixed in |
---|---|---|
limesurvey / limesurvey | 3.0.0 | 3.4.2 |
limesurvey / limesurvey | 2.7.0 | 2.73.1 |
limesurvey / limesurvey | 2.6.0 | 2.6.7 |
debian / debian_linux | 7.0 | 7.0.x |