CVE-2006-1209

PHP Advanced Transfer Manager 1.00 through 1.30 stores sensitive information, including password hashes, under the web root with insufficient access control, which allows remote attackers to download each password hash via a direct request for a users/[USERNAME] file.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:bugada_andrea:php_advanced_transfer_manager:1.20:*:*:*:*:*:*:*
cpe:2.3:a:bugada_andrea:php_advanced_transfer_manager:1.21:*:*:*:*:*:*:*
cpe:2.3:a:bugada_andrea:php_advanced_transfer_manager:1.00:*:*:*:*:*:*:*
cpe:2.3:a:bugada_andrea:php_advanced_transfer_manager:1.01:*:*:*:*:*:*:*
cpe:2.3:a:bugada_andrea:php_advanced_transfer_manager:1.02:*:*:*:*:*:*:*
cpe:2.3:a:bugada_andrea:php_advanced_transfer_manager:1.03:*:*:*:*:*:*:*
cpe:2.3:a:bugada_andrea:php_advanced_transfer_manager:1.22:*:*:*:*:*:*:*
cpe:2.3:a:bugada_andrea:php_advanced_transfer_manager:1.30:*:*:*:*:*:*:*

Information

Published : 2006-03-13 17:06

Updated : 2018-10-18 09:31


NVD link : CVE-2006-1209

Mitre link : CVE-2006-1209


JSON object : View

Advertisement

dedicated server usa

Products Affected

bugada_andrea

  • php_advanced_transfer_manager