CVE-2007-6395 Information

Description

Flat PHP Board 1.2 and earlier stores sensitive information under the web root with insufficient access control which allows remote attackers to obtain credentials via a direct request for the username php file for any user account in users/.

Reference

http://osvdb.org/43893 http://www.securityfocus.com/archive/1/484803/100/100/threaded http://www.securityfocus.com/bid/26782 https://www.exploit-db.com/exploits/4705

Share on: