Rule: -- Sid: 2370 -- Summary: This event is generated when an attempt is made to access config.conf, a component of the BugPort PHP web application running on a server. -- Impact: Information disclosure. -- Detailed Information: BugPort is a PHP application used for bug tracking purposes. It is possible for a remote user to view the configuration file for the application by making a request for the file using a web browser. -- Affected Systems: BugPort prior to version 1.099 -- Attack Scenarios: An attacker can view the configuration file for the server by using a web browser to request the file. -- Ease of Attack: Simple. -- False Positives: None known. -- False Negatives: None known. -- Corrective Action: Ensure the system is using an up to date version of the software and has had all vendor supplied patches applied. -- Contributors: Sourcefire Research Team Matt Watchinski Nigel Houghton -- Additional References: --