RunCMS 1.1 - Database Configuration Information Disclosure
Author: Majid NT
type: webapps
platform: php
port:
date_added: 2005-03-18
date_updated: 2013-05-06
verified: 1
codes: CVE-2005-0828;OSVDB-14890
tags:
aliases:
screenshot_url:
application_url:
source: https://www.securityfocus.com/bid/12848/info
RunCMS is reportedly affected by an information disclosure vulnerability. This issue is due to a failure in the application to secure sensitive information.
Exploitation of this vulnerability could lead to the disclosure of database configuration details, including the database name, user name and password.
RunCMS was formerly named E-Xoops.
http://www.example.com/[runcms]/class/debug/highlight.php?file=[runcmsinstallationpath]\mainfile.php&line=151#151