Vulnerabilities > CVE-2003-1401 - Credentials Management vulnerability in PHP Board PHP Board 1.0

047910
CVSS 5.8 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
NONE
network
php-board
CWE-255
exploit available

Summary

login.php in php-Board 1.0 stores plaintext passwords in $username.txt with insufficient access control under the web document root, which allows remote attackers to obtain sensitive information via a direct request.

Vulnerable Configurations

Part Description Count
Application
Php_Board
1

Common Weakness Enumeration (CWE)

Exploit-Db

descriptionPHP-Board 1.0 User Password Disclosure Vulnerability. CVE-2003-1401. Webapps exploit for php platform
idEDB-ID:22252
last seen2016-02-02
modified2003-02-15
published2003-02-15
reporterfrog
sourcehttps://www.exploit-db.com/download/22252/
titlePHP-Board 1.0 User Password Disclosure Vulnerability