Recruitment Software allows MySQL credentials disclosure

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 




PRODUCT DESCRIPTION
Recruitment Software (http://www.recruitment-agency-software.com/) is a free full featured web-based recruitment agency software product. An easy to use back-end administration gives you full control over your recruitment job listings. It has been checked that several institutions are relying on this software for their recruitment processes.

VULNERABILITY DESCRIPTION
Default installations allows anyone to read MySQL database credentials. The following URL shows an XML file with such information:
http://<server>/<root-dir>/admin/site.xml

WORKAROUND
Protect this resource with HTTP-based authentication

Rafael San Miguel Carrasco
Security Consultant
www.rafaelsanmiguel.com


[Index of Archives]     [Linux Security]     [Netfilter]     [PHP]     [Yosemite News]     [Linux Kernel]

  Powered by Linux