S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2018-7251 Scanner

CVE-2018-7251 scanner - Credential Disclosure vulnerability in Anchor

Est. Time~15 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.6k
Times Used
continuous scan runs
4.2k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2018-7251
9.8
CVSS

An issue was discovered in config/error.php in Anchor 0.12.3. The error log is exposed at an errors.log URI, and contains MySQL credentials if a MySQL error (such as "Too many connections") has occurred.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

Anchor is a popular content management system (CMS) that is widely used for developing and managing websites. It is a lightweight and flexible CMS that allows developers to create highly customized websites with minimal effort. Anchor is known for its user-friendly interface, powerful features, and excellent performance. It is an open-source CMS that can be downloaded and used for free.

CVE-2018-7251 is a vulnerability that was detected in Anchor 0.12.3. The vulnerability is related to an issue in config/error.php, which exposes the error log at an errors.log URI. This error log may contain sensitive information, such as MySQL credentials, if a MySQL error occurs. An attacker can exploit this vulnerability by sending a specially crafted request to the server, which could allow them to extract sensitive information from the error log.

When this vulnerability is exploited, it can lead to severe consequences. An attacker who gains access to sensitive information, such as MySQL credentials, can use it to launch further attacks. For instance, they can gain access to the database and extract confidential information, such as usernames, passwords, and other sensitive data. In some cases, they can even modify data, which can result in data breaches, financial loss, and reputational damage.

Thanks to the pro features of the s4e.io platform, users can easily and quickly learn about vulnerabilities in their digital assets. The platform offers comprehensive vulnerability assessment and management services that can help users identify and eliminate vulnerabilities in their websites and web applications. With advanced scanning, reporting, and remediation capabilities, users can ensure that their digital assets are secure and protected from cyber threats.

 

REFERENCES

Solution Advice

To protect against this vulnerability, the following precautions can be taken:

  • Ensure that the latest version of Anchor CMS is installed and updated regularly.
  • Limit access to the error log to authorized personnel only.
  • Use strong and secure passwords for all accounts, especially for database accounts.
  • Monitor logs regularly for any suspicious activity.
  • Use a web application firewall (WAF) that can detect and block attacks in real-time.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2018-7251 scanner - Credential Disclosure vulnerability in Anchor | S4E