CVE-2018-19513

Severity CVSS v4.0:
Pending analysis
Type:
CWE-532 Information Exposure Through Log Files
Publication date:
21/03/2019
Last modified:
22/03/2019

Description

In Webgalamb through 7.0, log files are exposed to the internet with predictable files/logs/sql_error_log/YYYY-MM-DD-sql_error_log.log filenames. The log file could contain sensitive client data (email addresses) and also facilitates exploitation of SQL injection errors.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ens:webgalamb:*:*:*:*:*:*:*:* 7.0 (including)