5
CVE-2006-0103
- EPSS 10.15%
- Veröffentlicht 06.01.2006 11:03:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
TinyPHPForum 3.6 and earlier stores the (1) users/[USERNAME].hash and (2) users/[USERNAME].email files under the web root with insufficient access control, which allows remote attackers to list all registered users and possibly obtain other sensitive information.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ralph Capper ≫ Tinyphpforum Version3.5
Ralph Capper ≫ Tinyphpforum Version3.6
Ralph Capper ≫ Tinyphpforum Version3.46
Ralph Capper ≫ Tinyphpforum Version3.47
Ralph Capper ≫ Tinyphpforum Version3.48
Ralph Capper ≫ Tinyphpforum Version3.49
Ralph Capper ≫ Tinyphpforum Version3.499
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 10.15% | 0.928 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.