PHPMyChat 0.14.5 does not remove or protect setup.php3 after installation, which allows attackers to obtain sensitive information including database passwords via a direct request.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2007-10-06T21:00:00Z

Updated: 2024-09-17T02:26:30.454Z

Reserved: 2007-10-06T00:00:00Z

Link: CVE-2004-2718

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2004-12-31T05:00:00.000

Modified: 2008-09-05T20:44:55.437

Link: CVE-2004-2718

cve-icon Redhat

No data.