5

CVE-2006-0103

Exploit
TinyPHPForum 3.6 and earlier stores the (1) users/[USERNAME].hash and (2) users/[USERNAME].email files under the web root with insufficient access control, which allows remote attackers to list all registered users and possibly obtain other sensitive information.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ralph CapperTinyphpforum Version3.5
Ralph CapperTinyphpforum Version3.6
Ralph CapperTinyphpforum Version3.46
Ralph CapperTinyphpforum Version3.47
Ralph CapperTinyphpforum Version3.48
Ralph CapperTinyphpforum Version3.49
Ralph CapperTinyphpforum Version3.499
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 10.15% 0.928
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.