[36954] in bugtraq
Clientexec Billing Software
daemon@ATHENA.MIT.EDU (bugtraq@rloxy.com)
Fri Oct 15 17:02:43 2004
Message-ID: <1097542996.416b2d54f3c46@webmail.rloxy.com>
Date: Mon, 11 Oct 2004 20:03:16 -0500
From: bugtraq@rloxy.com
To: bugtraq@securityfocus.com
MIME-Version: 1.0
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: 8bit
Clientexec is a php billing software with a target audience of webhosts. By
default there is a file called phpinfo.php in the main clientexec directory.
This can be access by anyone with a web browser. I looked through the
documentation and didn't find any reference to it. I then checked several
different companies using this piece of software and all had it in the same
place. I contacted the vendor and he said he would fix it. I know this sounds
silly, but many people that use this software are not familar with issues like
these let alone know what the phpinfo() function does.
William
----------------------------------------------------------------
This message was sent using IMP, the Internet Messaging Program.