CVE-2004-1219
paFileDB 3.1, when using sessions authentication and while the administrator logs on, allows remote attackers to read the administrator's password hash and conduct brute force password guessing attacks by listing the contents of the sessions directory…
Does this matter?
Lower severity and a low EPSS score (2.30%). Track it; it rarely justifies an emergency change on its own.
Description
paFileDB 3.1, when using sessions authentication and while the administrator logs on, allows remote attackers to read the administrator's password hash and conduct brute force password guessing attacks by listing the contents of the sessions directory and reading the associated file for the administrator session.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 2.30% probability · 82th percentile
- CISA KEV
- Not listed
- Affected
- php arena/pafiledb
- Source
- cve@mitre.org
References
- http://echo.or.id/adv/adv09-y3dips-2004.txt
- http://marc.info/?l=bugtraq&m=110245123927025&w=2
- http://www.securityfocus.com/bid/11818Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18364
- http://echo.or.id/adv/adv09-y3dips-2004.txt
- http://marc.info/?l=bugtraq&m=110245123927025&w=2
- http://www.securityfocus.com/bid/11818Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18364
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.