PHPMailList CVE-2006-3483 Multiple Information Disclosure Vulnerabilities

PHPMailList is prone to multiple information disclosure vulnerabilities because it stores sensitive information under the web document root iwth insufficient access control, which allows remote attackers to obtain email addresses of subscribers, configuration information, and the admin username and password via direct requests to 'list.dat' or 'l_config.dat'.


 

Privacy Statement
Copyright 2010, SecurityFocus