Ultimate PHP Board (UPB) 1.9.6 GOLD and earlier stores the users.dat file under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information on registered users via a direct request to db/users.dat.
References
Link | Resource |
---|---|
http://secunia.com/advisories/15732 | Patch Vendor Advisory |
http://marc.info/?l=bugtraq&m=111893777504821&w=2 |
Configurations
Configuration 1 (hide)
|
Information
Published : 2005-06-15 21:00
Updated : 2016-10-17 20:23
NVD link : CVE-2005-2005
Mitre link : CVE-2005-2005
JSON object : View
CWE
Products Affected
ultimate_php_board
- ultimate_php_board