5
CVE-2006-0103
- EPSS 4.08%
- Veröffentlicht 06.01.2006 11:03:00
- Zuletzt bearbeitet 16.06.2026 22:19:53
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
TinyPHPForum 3.6 and earlier stores the (1) users/[USERNAME].hash and (2) users/[USERNAME].email files under the web root with insufficient access control, which allows remote attackers to list all registered users and possibly obtain other sensitive information.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ralph Capper ≫ Tinyphpforum Version3.5
Ralph Capper ≫ Tinyphpforum Version3.6
Ralph Capper ≫ Tinyphpforum Version3.46
Ralph Capper ≫ Tinyphpforum Version3.47
Ralph Capper ≫ Tinyphpforum Version3.48
Ralph Capper ≫ Tinyphpforum Version3.49
Ralph Capper ≫ Tinyphpforum Version3.499
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 4.08% | 0.894 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
http://evuln.com/vulns/14/summary.html
http://secunia.com/advisories/18293
http://securityreason.com/securityalert/320
http://securitytracker.com/id?1015436
http://www.securityfocus.com/archive/1/420933/100/0/threaded
http://www.vupen.com/english/advisories/2006/0054
http://www.osvdb.org/22257
http://www.securityfocus.com/archive/1/431133/100/0/threaded
https://exchange.xforce.ibmcloud.com/vulnerabilities/24016