paFileDB 3.1, when using sessions authentication and while the administrator logs on, allows remote attackers to read the administrator's password hash and conduct brute force password guessing attacks by listing the contents of the sessions directory and reading the associated file for the administrator session.
References
Configurations
History
20 Nov 2024, 23:50
Type | Values Removed | Values Added |
---|---|---|
References | () http://echo.or.id/adv/adv09-y3dips-2004.txt - | |
References | () http://marc.info/?l=bugtraq&m=110245123927025&w=2 - | |
References | () http://www.securityfocus.com/bid/11818 - Vendor Advisory | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/18364 - |
Information
Published : 2005-01-10 05:00
Updated : 2024-11-20 23:50
NVD link : CVE-2004-1219
Mitre link : CVE-2004-1219
CVE.ORG link : CVE-2004-1219
JSON object : View
Products Affected
php_arena
- pafiledb
CWE