Description
WinMySQLadmin 1.1 stores the MySQL password in plain text in the my.ini file, which allows local users to obtain unathorized access the MySQL database.
Remediation
References
Related Vulnerabilities
PHP Data Processing Errors Vulnerability (CVE-2015-4025)
MySQL CVE-2015-4800 Vulnerability (CVE-2015-4800)
Oracle HTTP Server Other Vulnerability (CVE-2006-5349)
Jboss EAP Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2014-0248)
WordPress Plugin Canto Multiple Server-Side Request Forgery Vulnerabilities (1.7.0)