paFileDB 3.1, when using sessions authentication and while the administrator logs on, allows remote attackers to read the administrator's password hash and conduct brute force password guessing attacks by listing the contents of the sessions directory and reading the associated file for the administrator session.
References
Configurations
Information
Published : 2005-01-09 21:00
Updated : 2017-07-10 18:30
NVD link : CVE-2004-1219
Mitre link : CVE-2004-1219
JSON object : View
CWE
Products Affected
php_arena
- pafiledb