7.8
CVSSv2

CVE-2006-6866

Published: 31/12/2006 Updated: 19/10/2017
CVSS v2 Base Score: 7.8 | Impact Score: 6.9 | Exploitability Score: 10
VMScore: 785
Vector: AV:N/AC:L/Au:N/C:C/I:N/A:N

Vulnerability Summary

STphp EasyNews PRO 4.0 stores sensitive information under the web root with insufficient access control, which allows remote malicious users to obtain usernames, email addresses, and password hashes via a direct request for data/users.txt.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

stphp easynews 4.0

Exploits

=> EasyNews PRO News Publishing 40 Remote Password Disclosure Vulnerability <= => Affected Software: Easy News 40 PRO => Risk: Critical => Download: wwwstphpcom/scripts/EasyNews_PRO_4_0zip => Bugfounder: bd0rk => Contact: bd0rk[at]hackermailcom => Greets: str0ke, crashovernight, TheJT, Kacper Usage: ...