5
CVSSv2

CVE-2006-1209

Published: 14/03/2006 Updated: 14/02/2024
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

PHP Advanced Transfer Manager 1.00 up to and including 1.30 stores sensitive information, including password hashes, under the web root with insufficient access control, which allows remote malicious users to download each password hash via a direct request for a users/[USERNAME] file.

Vulnerable Product Search on Vulmon Subscribe to Product

bugada andrea php advanced transfer manager 1.00

bugada andrea php advanced transfer manager 1.22

bugada andrea php advanced transfer manager 1.21

bugada andrea php advanced transfer manager 1.03

bugada andrea php advanced transfer manager 1.20

bugada andrea php advanced transfer manager 1.02

bugada andrea php advanced transfer manager 1.01

bugada andrea php advanced transfer manager 1.30

Exploits

<? /* ::::::::: :::::::::: ::: ::: ::::::::::: ::: :+: :+: :+: :+: :+: :+: :+: +:+ +:+ +:+ +:+ +:+ +:+ +:+ +#+ +:+ +#++:++# +#+ +:+ +#+ +#+ +#+ +#+ +#+ +#+ +#+ +#+ +#+ #+# #+# #+# #+#+#+# #+# #+# ...