5

CVE-2006-0103

Exploit
TinyPHPForum 3.6 and earlier stores the (1) users/[USERNAME].hash and (2) users/[USERNAME].email files under the web root with insufficient access control, which allows remote attackers to list all registered users and possibly obtain other sensitive information.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ralph CapperTinyphpforum Version3.5
Ralph CapperTinyphpforum Version3.6
Ralph CapperTinyphpforum Version3.46
Ralph CapperTinyphpforum Version3.47
Ralph CapperTinyphpforum Version3.48
Ralph CapperTinyphpforum Version3.49
Ralph CapperTinyphpforum Version3.499
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 4.08% 0.894
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

http://evuln.com/vulns/14/summary.html
Vendor Advisory
http://secunia.com/advisories/18293
Vendor Advisory
http://securityreason.com/securityalert/320
http://securitytracker.com/id?1015436
Exploit
http://www.securityfocus.com/archive/1/420933/100/0/threaded
http://www.vupen.com/english/advisories/2006/0054
Vendor Advisory
http://www.osvdb.org/22257
http://www.securityfocus.com/archive/1/431133/100/0/threaded
https://exchange.xforce.ibmcloud.com/vulnerabilities/24016