login.php in php-Board 1.0 stores plaintext passwords in $username.txt with insufficient access control under the web document root, which allows remote attackers to obtain sensitive information via a direct request.
References
Configurations
History
No history.
Information
Published : 2003-12-31 05:00
Updated : 2025-04-03 01:03
NVD link : CVE-2003-1401
Mitre link : CVE-2003-1401
CVE.ORG link : CVE-2003-1401
JSON object : View
Products Affected
php_board
- php_board
CWE
CWE-255
Credentials Management Errors