Description
PHPBlogger stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing an admin password hash via a direct request for data/pref.db. NOTE: this can be easily leveraged for administrative access because composing the authentication cookie only requires the password hash, not the cleartext version.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2007-4141 | PHPBlogger stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing an admin password hash via a direct request for data/pref.db. NOTE: this can be easily leveraged for administrative access because composing the authentication cookie only requires the password hash, not the cleartext version. |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-07T14:46:39.364Z
Reserved: 2007-08-03T00:00:00.000Z
Link: CVE-2007-4157
No data.
Status : Modified
Published: 2007-08-03T21:17:00.000
Modified: 2026-04-23T00:35:47.467
Link: CVE-2007-4157
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD