login.php in php-Board 1.0 stores plaintext passwords in $username.txt with insufficient access control under the web document root, which allows remote attackers to obtain sensitive information via a direct request.
References
Configurations
Information
Published : 2003-12-30 21:00
Updated : 2017-07-28 18:29
NVD link : CVE-2003-1401
Mitre link : CVE-2003-1401
JSON object : View
CWE
CWE-255
Credentials Management Errors
Products Affected
php_board
- php_board