CVE-2008-5855
06.01.2009, 17:30
myPHPscripts Login Session 2.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to discover usernames, e-mail addresses, and password hashes via a direct request for users.txt.Enginsight
Vendor | Product | Version |
---|---|---|
myphpscripts | login_session | 2.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References