Wuff MovieDB Password Disclosure Vulnerability

BID:3823

Info

Wuff MovieDB Password Disclosure Vulnerability

Bugtraq ID: 3823
Class: Design Error
CVE:
Remote: No
Local: Yes
Published: Jan 05 2002 12:00AM
Updated: Jan 05 2002 12:00AM
Credit: Published in the Wuff MovieDB changelog on January 5, 2002.
Vulnerable: Wuff MovieDB 1.35
Not Vulnerable: Wuff MovieDB 1.36

Discussion

Wuff MovieDB Password Disclosure Vulnerability

Wuff MovieDB is a MySQL-Database which enables users to catalogue various media type files (VCD, SVCD, DVD, movies) with cover art. MovieDB includes a PHP front end to access and modify the database content.

Due to a flaw in MovieDB, a user can gain knowledge of another user's password.

This is achievable when a user is logging into the program. MovieDB is designed in such a way that when a user attempts to log into the program, the password field does not conceal the password, with for example asterisks. The password entered is in plain text, any on lookers may clearly read the authentication info and log in as that user.

Exploit / POC

Wuff MovieDB Password Disclosure Vulnerability

No exploit code is required.

Solution / Fix

Wuff MovieDB Password Disclosure Vulnerability

Solution:
Wuff has addressed this in MovieDB 1.36:


Wuff MovieDB 1.35

References

Wuff MovieDB Password Disclosure Vulnerability

References:

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report