PAFileDB Password Hash Disclosure Vulnerability
BID:11818
Info
PAFileDB Password Hash Disclosure Vulnerability
| Bugtraq ID: | 11818 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 04 2004 12:00AM |
| Updated: | Dec 04 2004 12:00AM |
| Credit: | Discovered by y3dips <[email protected]>. |
| Vulnerable: |
PHP Arena paFileDB 3.1 |
| Not Vulnerable: | |
Discussion
PAFileDB Password Hash Disclosure Vulnerability
paFileDB reportedly allows any users to view the password hash of other accounts, including the administrator. This issue only exists if session authentication is used rather than cookie authentication.
paFileDB reportedly allows any users to view the password hash of other accounts, including the administrator. This issue only exists if session authentication is used rather than cookie authentication.
Exploit / POC
PAFileDB Password Hash Disclosure Vulnerability
There is no exploit required.
There is no exploit required.
Solution / Fix
PAFileDB Password Hash Disclosure Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
PAFileDB Password Hash Disclosure Vulnerability
References:
References:
- Multiple Vulnerabilities in paFileDB 3.1 (y3dips)
- paFileDB Homepage (PHP Arena)