Medium
CVSS 5.0
Overview
WeBid auction script 0.5.4 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain SQL query logs via a direct request for logs/cron.log.
WeBid auction script 0.5.4 stores sensitive information under the web root with ...
WeBid auction script 0.5.4 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain SQL query logs via a direct request for logs/cron.log.
This vulnerability is rated 🟡 MEDIUM.
Recommended actions: