Back to search
CVE-2007-6395
Published: Dec 17, 2007
Modified: Aug 7, 2024
PUBLISHED
Description
Flat PHP Board 1.2 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain credentials via a direct request for the username php file for any user account in users/.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
20071209 Flat PHP Board <= 1.2 Multiple Vulnerabilities
mailing-list
x_refsource_BUGTRAQ
4705
exploit
x_refsource_EXPLOIT-DB
26782
vdb-entry
x_refsource_BID
43893
vdb-entry
x_refsource_OSVDB
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now