VulnerabilityModified
CVE-2006-1207
PHP Upload Center stores password hashes under the web root with insufficient access control, which allows remote attackers to download each password hash via a direct request for the upload/users/[USERNAME] file.
MEDIUM 5.0EPSS 1.55%
Does this matter?
Lower severity and a low EPSS score (1.55%). Track it; it rarely justifies an emergency change on its own.
Description
PHP Upload Center stores password hashes under the web root with insufficient access control, which allows remote attackers to download each password hash via a direct request for the upload/users/[USERNAME] file.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 1.55% probability · 74th percentile
- CISA KEV
- Not listed
- Affected
- sergey korostel/php upload center
- Source
- cve@mitre.org
References
- http://biyosecurity.be/bugs/phpuploadcenter2.txtExploit
- http://www.blogcu.com/Liz0ziM/317250/URL Repurposed
- http://www.osvdb.org/23627
- http://www.scripts-by.net/PHP/File-Manipulation/php-upload-center.htmlURL Repurposed
- http://www.securityfocus.com/archive/1/427215/100/0/threaded
- http://biyosecurity.be/bugs/phpuploadcenter2.txtExploit
- http://www.blogcu.com/Liz0ziM/317250/URL Repurposed
- http://www.osvdb.org/23627
- http://www.scripts-by.net/PHP/File-Manipulation/php-upload-center.htmlURL Repurposed
- http://www.securityfocus.com/archive/1/427215/100/0/threaded
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.