CVE-2013-1807

Php-fusion < 7.02.05 - Access Control

Title source: rule

Description

PHP-Fusion before 7.02.06 stores backup files with predictable filenames in an unrestricted directory under the web document root, which might allow remote attackers to obtain sensitive information via a direct request to the backup file in administration/db_backups/.

Exploits (1)

exploitdb WRITEUP
webappsphp
https://www.exploit-db.com/exploits/24562

Scores

EPSS 0.1803
EPSS Percentile 95.2%

Details

CWE
CWE-264
Status published
Products (5)
php-fusion/php-fusion 7.02.01
php-fusion/php-fusion 7.02.02
php-fusion/php-fusion 7.02.03
php-fusion/php-fusion 7.02.04
php-fusion/php-fusion < 7.02.05
Published Apr 30, 2014
Tracked Since Feb 18, 2026