phpProfiles before 2.1.1 uses world writable permissions for certain profile files and directories, which allows local users to modify or delete files, related to (1) users/include/do_makeprofile.inc.php and (2) users/include/copy.inc.php.
References
Configurations
Information
Published : 2006-12-26 15:28
Updated : 2017-07-28 18:29
NVD link : CVE-2006-6743
Mitre link : CVE-2006-6743
JSON object : View
CWE
Products Affected
phpprofiles
- phpprofiles