VulnerabilityModified
CVE-2007-6395
Flat PHP Board 1.2 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain credentials via a direct request for the username php file for any user account in users/.
MEDIUM 5.0EPSS 6.24%
Does this matter?
Lower severity and a low EPSS score (6.24%). Track it; it rarely justifies an emergency change on its own.
Description
Flat PHP Board 1.2 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain credentials via a direct request for the username php file for any user account in users/.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 6.24% probability · 93th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- flat php/board
- Source
- cve@mitre.org
References
- http://osvdb.org/43893
- http://www.securityfocus.com/archive/1/484803/100/100/threaded
- http://www.securityfocus.com/bid/26782
- https://www.exploit-db.com/exploits/4705
- http://osvdb.org/43893
- http://www.securityfocus.com/archive/1/484803/100/100/threaded
- http://www.securityfocus.com/bid/26782
- https://www.exploit-db.com/exploits/4705
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.