Field Assessment
AI analysis pending.
CVE
CVE-2002-1886
Severity
MEDIUM
CVSS
5
EPSS
2.84%
Original Filing — NVD Description
TightAuction 3.0 stores config.inc under the web document root with insufficient access control, which allows remote attackers to obtain the database username and password.