Vulnerabilities > Phptoys > Micro Login System

DATE CVE VULNERABILITY TITLE RISK
2007-11-01 CVE-2007-5787 Permissions, Privileges, and Access Controls vulnerability in PHPtoys Micro Login System 1.0
Micro Login System 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a file containing a password via a direct request for userpwd.txt.
network
low complexity
phptoys CWE-264
5.0