paFileDB 3.1, when using sessions authentication and while the administrator logs on, allows remote attackers to read the administrator's password hash and conduct brute force password guessing attacks by listing the contents of the sessions directory and reading the associated file for the administrator session.
                
            References
                    Configurations
                    Information
                Published : 2005-01-09 21:00
Updated : 2017-07-10 18:30
NVD link : CVE-2004-1219
Mitre link : CVE-2004-1219
JSON object : View
CWE
                Products Affected
                php_arena
- pafiledb


