header-logo
Suggest Exploit
vendor:
php-board
by:
SecurityFocus
7,5
CVSS
HIGH
php-board User Information Disclosure
200
CWE
Product Name: php-board
Affected Version From: php-board 1.0
Affected Version To: php-board 1.0
Patch Exists: YES
Related CWE: CVE-2002-1390
CPE: a:php-board:php-board:1.0
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: None
2002

php-board User Information Disclosure

php-board is vulnerable to an information disclosure vulnerability due to insufficient access control. An attacker can access user files and gain access to php-board user and administrative passwords by requesting the user files via the web.

Mitigation:

Restrict access to the user files.
Source

Exploit-DB raw data:

source: https://www.securityfocus.com/bid/6862/info

php-board user information is stored in flat files on the system hosting the software. Access to the files via the web is not sufficiently restricted. Remote attackers may request user files and gain access to php-board user and administrative passwords.

http://www.example.com/user/[NICKNAME].txt