|
concrete5 contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when a direct request is sent to files/tmp/, which is incorrectly set to be world-readable, which will disclose session information to a remote attacker, allowing for them to more easily conduct session hijacking attacks.
|