CVE-2013-1402

Digitiliti Digilibe - Information Disclosure

Title source: rule
STIX 2.1

Description

DigiLIBE 3.4 and possibly other versions sends a redirect but does not exit, which allows remote attackers to obtain sensitive configuration information via a direct request to configuration/general_configuration.html.

Exploits (1)

exploitdb WRITEUP VERIFIED
by Robert Gilbert · textwebappsphp
https://www.exploit-db.com/exploits/38234

References (1)

Core 1
Core References
Exploit mailing-list x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2013-01/0095.html

Scores

EPSS 0.1132
EPSS Percentile 93.6%

Details

CWE
CWE-200
Status published
Products (1)
digitiliti/digilibe 3.4
Published Feb 14, 2013
Tracked Since Feb 18, 2026