Vulnerabilities > CVE-2005-2192 - Remote Security vulnerability in Alexander Palmo Simple PHP Blog 0.4.0

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
network
low complexity
alexander-palmo
exploit available

Summary

SimplePHPBlog 0.4.0 stores password hashes in config/password.txt with insufficient access control, which allows remote attackers to obtain passwords via a brute force attack.

Vulnerable Configurations

Part Description Count
Application
Alexander_Palmo
1

Exploit-Db

descriptionSimple PHP Blog <= 0.4.0 Multiple Remote Exploits. CVE-2005-2192,CVE-2005-2733,CVE-2005-2787. Webapps exploit for php platform
idEDB-ID:1191
last seen2016-01-31
modified2005-09-01
published2005-09-01
reporterKenneth Belva
sourcehttps://www.exploit-db.com/download/1191/
titleSimple PHP Blog <= 0.4.0 - Multiple Remote Exploits