Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Date: Wed, 25 Mar 2009 21:14:17 -0400 (EDT)
From: "Steven M. Christey" <>
cc: Steven Christey <>
Subject: Re: CVE request: API key disclosure in piwik

Name: CVE-2009-1085
Status: Candidate
Reference: MLIST:[oss-security] 20090323 CVE request: API key disclosure in piwik
Reference: URL:
Reference: MISC:
Reference: CONFIRM:

Piwik 0.2.32 and earlier stores sensitive information under the web
root with insufficient access control, which allows remote attackers
to obtain the API key and other sensitive information via a direct
request for misc/cron/

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.