CVE-2008-5855
EUVD-2008-582506.01.2009, 17:30
myPHPscripts Login Session 2.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to discover usernames, e-mail addresses, and password hashes via a direct request for users.txt.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| myphpscripts | login_session | 2.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References