SimpleBBS 1.0.6 - 'users.php' Insecure File Permissions



EKU-ID: 27822 CVE: OSVDB-7045 OSVDB-ID:
Author: flur Published: 2003-03-07 Verified: Verified
Download:

Rating

☆☆☆☆☆
Home


source: https://www.securityfocus.com/bid/7045/info

SimpleBBS reportedly creates sensitive files with world-readable permissions.
As a result anyone who has access to SimpleBBS web resources may access confidential information stored in the SimpleBBS user database.

This vulnerability was reported for SimpleBBS 1.0.6. It is not known if earlier versions are affected by this vulnerability.

http://www.example.com/simplebbs/users/users.php