5.8
CVSSv2

CVE-2003-1401

Published: 31/12/2003 Updated: 29/07/2017
CVSS v2 Base Score: 5.8 | Impact Score: 4.9 | Exploitability Score: 8.6
VMScore: 585
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N

Vulnerability Summary

login.php in php-Board 1.0 stores plaintext passwords in $username.txt with insufficient access control under the web document root, which allows remote malicious users to obtain sensitive information via a direct request.

Vulnerable Product Search on Vulmon Subscribe to Product

php board php board 1.0

Exploits

source: wwwsecurityfocuscom/bid/6862/info php-board user information is stored in flat files on the system hosting the software Access to the files via the web is not sufficiently restricted Remote attackers may request user files and gain access to php-board user and administrative passwords wwwexamplecom/user/[NICKNAME]txt ...