Vulnerabilities (CVE)

Filtered by vendor Amarok Subscribe
Filtered by product Web Frontend
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2005-2029 1 Amarok 1 Web Frontend 2024-02-28 7.5 HIGH N/A
amaroK Web Frontend 1.3 stores the globals.inc file under the web root without a .php extension and insufficient access control, which allows remote attackers to obtain the database username and password via a direct request to the file.