[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250038

 
 

909

 
 

195843

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2005-3049Date: (C)2005-09-23   (M)2023-12-22


PhpMyFaq 1.5.1 stores data files under the web document root with insufficient access control and predictable filenames, which allows remote attackers to obtain sensitive information via a direct request to the data/tracking[DATE] file.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 5.0
Exploit Score: 10.0
Impact Score: 2.9
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: LOW
Authentication: NONE
Confidentiality: PARTIAL
Integrity: NONE
Availability: NONE
  
Reference:
SECTRACK-1014968
BID-14930
SECUNIA-16933
OSVDB-19670
http://marc.info/?l=bugtraq&m=112749230124091&w=2
http://rgod.altervista.org/phpmyfuck151.html
phpmyfaq-log-user-information-disclosure(22405)

CPE    1
cpe:/a:phpmyfaq:phpmyfaq:1.5.1

© SecPod Technologies