CVE-2006-5027 - Rufescent Shop
Description
Jeroen Vennegoor JevonCMS possibly pre alpha allows remote attackers to obtain sensitive information via a direct request for php/main/phplib files (1) db_msql.inc (2) db_mssql.inc (3) db_mysql.inc (4) db_oci8.inc (5) db_odbc.inc (6) db_oracle.inc and (7) db_pgsql.inc; and (8) db_sybase.inc which reveals the path in various error messages.
Reference
http://securityreason.com/securityalert/1638 https://exchange.xforce.ibmcloud.com/vulnerabilities/29126 http://www.securityfocus.com/archive/1/446741/100/0/threaded