5
CVSSv2

CVE-2008-5855

Published: 06/01/2009 Updated: 29/09/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

myPHPscripts Login Session 2.0 stores sensitive information under the web root with insufficient access control, which allows remote malicious users to discover usernames, e-mail addresses, and password hashes via a direct request for users.txt.

Vulnerable Product Search on Vulmon Subscribe to Product

myphpscripts login session 2.0

Exploits

[START] #################################################################################################################### [0x01] Informations: Script : myPHPscripts Login Session 20 Download : wwwhotscriptscom/jumpphp?listing_id=69881&jump_type=1 Vulnerability : XSS / Database Disclosure Author : Osirys Co ...