5
CVSSv2

CVE-2006-0103

Published: 06/01/2006 Updated: 19/10/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

TinyPHPForum 3.6 and previous versions stores the (1) users/[USERNAME].hash and (2) users/[USERNAME].email files under the web root with insufficient access control, which allows remote malicious users to list all registered users and possibly obtain other sensitive information.

Vulnerable Product Search on Vulmon Subscribe to Product

ralph capper tinyphpforum 3.47

ralph capper tinyphpforum 3.48

ralph capper tinyphpforum 3.49

ralph capper tinyphpforum 3.499

ralph capper tinyphpforum 3.46

ralph capper tinyphpforum 3.5

ralph capper tinyphpforum 3.6

Exploits

source: wwwsecurityfocuscom/bid/16163/info TinyPHPForum is prone to multiple directory traversal vulnerabilities These issues are due to a failure in the application to properly sanitize user-supplied input An attacker can exploit these vulnerabilities to retrieve arbitrary files from the vulnerable system in the context of the Web ser ...