CVE-2015-5959

Severity CVSS v4.0:
Pending analysis
Type:
CWE-200 Information Leak / Disclosure
Publication date:
06/09/2017
Last modified:
20/04/2025

Description

Froxlor before 0.9.33.2 with the default configuration/setup might allow remote attackers to obtain the database password by reading /logs/sql-error.log.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:froxlor:froxlor:*:*:*:*:*:*:*:* 0.9.33.1 (including)