PT-2006-1441 · Rcblog · Rcblog

·

CVE-2006-0370

·

Publicado

2006-01-22

·

Atualizado

2024-02-14

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions RCBlog version 1.03
Description The issue allows remote attackers to view account names and MD5 password hashes due to insufficient access control of the data and config directories stored under the web root.
Recommendations For RCBlog version 1.03, consider restricting access to the data and config directories to prevent remote viewing of sensitive information. As a temporary workaround, restrict access to these directories until a proper fix is applied.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-0370

Produtos afetados

Rcblog