Vulnerabilities > CVE-2006-2946 - Remote Security vulnerability in Dmx Forum

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
network
low complexity
dmx-forum
exploit available

Summary

Dmx Forum 2.1a stores _includes/bd.inc under the web root with insufficient access control, which allows remote attackers to obtain database username and password information.

Vulnerable Configurations

Part Description Count
Application
Dmx_Forum
1

Exploit-Db

descriptionDmx Forum <= 2.1a (edit.php) Remote Password Disclosure Exploit. CVE-2006-2946,CVE-2006-2947. Webapps exploit for php platform
idEDB-ID:1882
last seen2016-01-31
modified2006-06-05
published2006-06-05
reporterDarkFig
sourcehttps://www.exploit-db.com/download/1882/
titleDmx Forum <= 2.1a edit.php Remote Password Disclosure Exploit