CVE Vulnerabilities

CVE-2006-1209

Published: Mar 14, 2006 | Modified: Oct 18, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

PHP Advanced Transfer Manager 1.00 through 1.30 stores sensitive information, including password hashes, under the web root with insufficient access control, which allows remote attackers to download each password hash via a direct request for a users/[USERNAME] file.

Affected Software

Name Vendor Start Version End Version
Php_advanced_transfer_manager Bugada_andrea 1.00 (including) 1.00 (including)
Php_advanced_transfer_manager Bugada_andrea 1.01 (including) 1.01 (including)
Php_advanced_transfer_manager Bugada_andrea 1.02 (including) 1.02 (including)
Php_advanced_transfer_manager Bugada_andrea 1.03 (including) 1.03 (including)
Php_advanced_transfer_manager Bugada_andrea 1.20 (including) 1.20 (including)
Php_advanced_transfer_manager Bugada_andrea 1.21 (including) 1.21 (including)
Php_advanced_transfer_manager Bugada_andrea 1.22 (including) 1.22 (including)
Php_advanced_transfer_manager Bugada_andrea 1.30 (including) 1.30 (including)

References