VulnerabilityModified
CVE-2008-5855
myPHPscripts Login Session 2.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to discover usernames, e-mail addresses, and password hashes via a direct request for users.txt.
MEDIUM 5.0EPSS 2.61%
Does this matter?
Lower severity and a low EPSS score (2.61%). Track it; it rarely justifies an emergency change on its own.
Description
myPHPscripts Login Session 2.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to discover usernames, e-mail addresses, and password hashes via a direct request for users.txt.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 2.61% probability · 85th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- myphpscripts/login session
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/33253Vendor Advisory
- http://securityreason.com/securityalert/4873
- https://exchange.xforce.ibmcloud.com/vulnerabilities/47502
- https://www.exploit-db.com/exploits/7526
- http://secunia.com/advisories/33253Vendor Advisory
- http://securityreason.com/securityalert/4873
- https://exchange.xforce.ibmcloud.com/vulnerabilities/47502
- https://www.exploit-db.com/exploits/7526
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.