CVE-2002-1886
TightAuction 3.0 - Info Disclosure
Title source: llmDescription
TightAuction 3.0 stores config.inc under the web document root with insufficient access control, which allows remote attackers to obtain the database username and password.
Exploits (1)
Scores
EPSS
0.0525
EPSS Percentile
89.8%
Classification
Status
draft
Affected Products (1)
tightauction/tightauction
Timeline
Published
Dec 31, 2002
Tracked Since
Feb 18, 2026