Spyke PHP Board Information Disclosure Vulnerability
BID:7856
Info
Spyke PHP Board Information Disclosure Vulnerability
| Bugtraq ID: | 7856 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 09 2003 12:00AM |
| Updated: | Jun 09 2003 12:00AM |
| Credit: | Discovery of this vulnerability credited to "Marc Bromm" <[email protected]>. |
| Vulnerable: |
Spyke-Online Spyke PHP Board 2.1 |
| Not Vulnerable: | |
Discussion
Spyke PHP Board Information Disclosure Vulnerability
A vulnerability has been reported for Spyke's PHP Board that may result in an attacker obtaining access to sensitive information such as authentication credentials.
The vulnerability exists because the CMS uses plain text files for storage of configuration data.
A vulnerability has been reported for Spyke's PHP Board that may result in an attacker obtaining access to sensitive information such as authentication credentials.
The vulnerability exists because the CMS uses plain text files for storage of configuration data.
Exploit / POC
Spyke PHP Board Information Disclosure Vulnerability
There is no exploit required.
There is no exploit required.
Solution / Fix
Spyke PHP Board Information Disclosure Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Spyke PHP Board Information Disclosure Vulnerability
References:
References:
- Spyke-Online (Spyke-Online)
- Several bugs found in "Spyke's PHP Board" ("Marc Bromm"
)