CVE-2007-4937 Information

Description

CS Guestbook stores sensitive information under the web root with insufficient access control which allows remote attackers to obtain the admin name and MD5 password hash via a direct request for base/usr/0.php.

Reference

http://secunia.com/advisories/26805 http://securityreason.com/securityalert/3147 http://www.securityfocus.com/archive/1/479194/100/0/threaded http://www.securityfocus.com/bid/25652 https://exchange.xforce.ibmcloud.com/vulnerabilities/36587

Share on: