Ultimate PHP Board (UPB) 1.9.6 GOLD and earlier stores the users.dat file under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information on registered users via a direct request to db/users.dat.
References
Link | Resource |
---|---|
http://marc.info/?l=bugtraq&m=111893777504821&w=2 | |
http://secunia.com/advisories/15732 | Patch Vendor Advisory |
http://marc.info/?l=bugtraq&m=111893777504821&w=2 | |
http://secunia.com/advisories/15732 | Patch Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
20 Nov 2024, 23:58
Type | Values Removed | Values Added |
---|---|---|
References | () http://marc.info/?l=bugtraq&m=111893777504821&w=2 - | |
References | () http://secunia.com/advisories/15732 - Patch, Vendor Advisory |
Information
Published : 2005-06-16 04:00
Updated : 2024-11-20 23:58
NVD link : CVE-2005-2005
Mitre link : CVE-2005-2005
CVE.ORG link : CVE-2005-2005
JSON object : View
Products Affected
ultimate_php_board
- ultimate_php_board
CWE