PHP-Board User Password Disclosure Vulnerability
BID:6862
Info
PHP-Board User Password Disclosure Vulnerability
| Bugtraq ID: | 6862 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 15 2003 12:00AM |
| Updated: | Feb 15 2003 12:00AM |
| Credit: | Discovery of this issue is credited to Frog Man <[email protected]>. |
| Vulnerable: |
php-board php-board 1.0 |
| Not Vulnerable: | |
Discussion
PHP-Board User Password Disclosure Vulnerability
php-board user information is stored in flat files on the system hosting the software. Access to the files via the web is not sufficiently restricted. Remote attackers may request user files and gain access to php-board user and administrative passwords.
php-board user information is stored in flat files on the system hosting the software. Access to the files via the web is not sufficiently restricted. Remote attackers may request user files and gain access to php-board user and administrative passwords.
Solution / Fix
PHP-Board User Password Disclosure Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
PHP-Board User Password Disclosure Vulnerability
References:
References:
- 5 holes, Part 8 (Frog Man)
- php-board Homepage (php-board)