CVE-2007-0518 Information
Feb 14, 2021
cve
Description
Scriptsez Smart PHP Subscriber (aka subscribe) stores sensitive information under the web root with insufficient access control which allows remote attackers to obtain encoded passwords via a direct request for pwd.txt.
Reference
http://osvdb.org/32946 http://secunia.com/advisories/23886 http://securityreason.com/securityalert/2183 http://www.securityfocus.com/archive/1/457852/100/0/threaded https://exchange.xforce.ibmcloud.com/vulnerabilities/31701
Share on: