Vulnerabilities > CVE-2007-6399 - Credentials Management vulnerability in Myupb Flat PHP Board

047910
CVSS 6.5 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
SINGLE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
myupb
CWE-255
exploit available

Summary

index.php in Flat PHP Board 1.2 and earlier allows remote authenticated users to obtain the password for the current user account by reading the password parameter value in the HTML source for the page generated by a profile action.

Vulnerable Configurations

Part Description Count
Application
Myupb
1

Common Weakness Enumeration (CWE)

Exploit-Db

descriptionFlat PHP Board <= 1.2 Multiple Vulnerabilities. CVE-2007-6395,CVE-2007-6396,CVE-2007-6397,CVE-2007-6398,CVE-2007-6399. Webapps exploit for php platform
fileexploits/php/webapps/4705.txt
idEDB-ID:4705
last seen2016-01-31
modified2007-12-09
platformphp
port
published2007-12-09
reporterKiNgOfThEwOrLd
sourcehttps://www.exploit-db.com/download/4705/
titleFlat PHP Board <= 1.2 - Multiple Vulnerabilities
typewebapps