CVE-2002-2322

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
31/12/2002
Last modified:
05/09/2008

Description

Ultimate PHP Board (UPB) 1.0b stores the users.dat data file under the web root with insufficient access control, which allows remote attackers to obtain usernames and passwords.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ultimate_php_board:ultimate_php_board:1.0_beta:*:*:*:*:*:*:*