VulnerabilityModified
CVE-2002-2322
Ultimate PHP Board (UPB) 1.0b stores the users.dat data file under the web root with insufficient access control, which allows remote attackers to obtain usernames and passwords.
MEDIUM 5.0EPSS 1.39%
Does this matter?
Lower severity and a low EPSS score (1.39%). Track it; it rarely justifies an emergency change on its own.
Description
Ultimate PHP Board (UPB) 1.0b stores the users.dat data file under the web root with insufficient access control, which allows remote attackers to obtain usernames and passwords.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 1.39% probability · 71th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- ultimate php board/ultimate php board
- Source
- cve@mitre.org
References
- http://archives.neohapsis.com/archives/bugtraq/2002-10/0016.html
- http://www.iss.net/security_center/static/10300.php
- http://www.securityfocus.com/bid/5858
- http://archives.neohapsis.com/archives/bugtraq/2002-10/0016.html
- http://www.iss.net/security_center/static/10300.php
- http://www.securityfocus.com/bid/5858
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.