Vulnerabilities > CVE-2006-3753 - Remote Security vulnerability in Professional Home Page Tools Guestbook

047910
CVSS 6.4 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
NONE
network
low complexity
professional-home-page-tools

Summary

setcookie.php for the administration login in Professional Home Page Tools Guestbook records the hash of the administrator password in a cookie, which allows attackers to conduct brute force password guessing attacks after obtaining the hash.

Vulnerable Configurations

Part Description Count
Application
Professional_Home_Page_Tools
1