Insecure File Storage in Basilix Webmail 0.9.7beta and Other Versions

Insecure File Storage in Basilix Webmail 0.9.7beta and Other Versions

CVE-2001-1044 · HIGH Severity

AV:N/AC:L/AU:N/C:P/I:P/A:P

Basilix Webmail 0.9.7beta, and possibly other versions, stores *.class and *.inc files under the document root and does not restrict access, which could allows remote attackers to obtain sensitive information such as MySQL passwords and usernames from the mysql.class file.

Learn more about our Cis Benchmark Audit For Microsoft Sql Server.