Vulnerable Systems:
* Quicksilver Forums version 1.4.2
* PowerDNS Administrator version 1.1.8
* QSF Portal version 1.4.5
The database backup functionality stores the database backup with a semi-predictable file name inside the web root. This can be exploited to download the backup by guessing the file name.
NOTE: Additionally, database backup files are changed to world read- and writable access permissions.
Workaround:
Do not use the database backup functionality. Restrict access to existing backup files.
Disclosure Timeline:
24/02/2010 - Vendor of QSF Portal and PowerDNS Administrator notified.
10/03/2010 - Vendor of Quicksilver Forums notified.
17/03/2010 - Public disclosure.