Description
Attachmax Dolphin 2.1.0 and earlier does not properly protect info.php in the main folder, which allows remote attackers to obtain sensitive information via a direct request, which invokes the phpinfo function. NOTE: some of these details are obtained from third party information.
Affected products
- attachmax / dolphin2.1.0 – 2.1.0
References
- MISChttp://e-rdc.org/v1/news.php?readmore=108
- VENDOR_ADVISORYhttp://secunia.com/advisories/31794
- EXPLOIThttps://www.exploit-db.com/exploits/6468
- MISChttp://osvdb.org/48271
- MISChttp://www.securityfocus.com/archive/1/496427/100/0/threaded
- MISChttp://www.securityfocus.com/bid/31207
- MISChttp://securityreason.com/securityalert/4307