HIGH · 7.5

CVE-2005-2029

amaroK Web Frontend 1.3 stores the globals.inc file under the web root without a .php extension and insufficient access control, which allows remote attackers to obtain the database username and passw...

Vulnerability Description

amaroK Web Frontend 1.3 stores the globals.inc file under the web root without a .php extension and insufficient access control, which allows remote attackers to obtain the database username and password via a direct request to the file.

CVSS Score

7.5

HIGH

AV:N/AC:L/Au:N/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
AmarokWeb Frontend1.3

References

FAQ

What is CVE-2005-2029?

CVE-2005-2029 is a vulnerability with a CVSS score of 7.5 (HIGH). amaroK Web Frontend 1.3 stores the globals.inc file under the web root without a .php extension and insufficient access control, which allows remote attackers to obtain the database username and passw...

How severe is CVE-2005-2029?

CVE-2005-2029 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2005-2029?

Check the references section above for vendor advisories and patch information. Affected products include: Amarok Web Frontend.