Vulnerabilities
Vulnerable Software
Froxlor:  >> Froxlor  >> 0.10.14  Security Vulnerabilities
Froxlor through 0.10.29.1 allows SQL injection in Database/Manager/DbManagerMySQL.php via a custom DB name.
CVSS Score
9.8
EPSS Score
0.055
Published
2021-10-12
An issue was discovered in Froxlor through 0.10.15. The installer wrote configuration parameters including passwords into files in /tmp, setting proper permissions only after writing the sensitive data. A local attacker could have disclosed the information if he read the file at the right time, because of _createUserdataConf in install/lib/class.FroxlorInstall.php.
CVSS Score
5.5
EPSS Score
0.001
Published
2020-03-09


Contact Us

Shodan ® - All rights reserved