Security Advisory

CVE-2006-0103

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2006-01-06 11:00:00
Last updated 2024-08-07 16:25:33
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

TinyPHPForum 3.6 and earlier stores the (1) users/[USERNAME].hash and (2) users/[USERNAME].email files under the web root with insufficient access control, which allows remote attackers to list all registered users and possibly obtain other sensitive information.