CVE-2009-0964

UserView_list.php in PHPRunner 4.2, and possibly earlier, stores passwords in cleartext in the database, which allows attackers to gain privileges. NOTE: this can be leveraged with a separate SQL injection vulnerability to obtain passwords remotely without authentication.
Configurations

Configuration 1 (hide)

cpe:2.3:a:xlinesoft:phprunner:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2009-03-19 10:30

Updated : 2025-04-09 00:30


NVD link : CVE-2009-0964

Mitre link : CVE-2009-0964

CVE.ORG link : CVE-2009-0964


JSON object : View

Products Affected

xlinesoft

  • phprunner
CWE
CWE-312

Cleartext Storage of Sensitive Information