SimplePHPBlog 0.4.0 stores password hashes in config/password.txt with insufficient access control, which allows remote malicious users to obtain passwords via a brute force attack.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
alexander palmo simple php blog 0.4.0 |