CVE Vulnerabilities

CVE-2009-1051

Published: Mar 24, 2009 | Modified: Oct 10, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

FubarForum 1.6 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing user credentials via a direct request for user.tsv.

Affected Software

Name Vendor Start Version End Version
Fubarforum Chaozz * 1.6 (including)
Fubarforum Chaozz 1.0 (including) 1.0 (including)
Fubarforum Chaozz 1.1 (including) 1.1 (including)
Fubarforum Chaozz 1.2 (including) 1.2 (including)
Fubarforum Chaozz 1.3 (including) 1.3 (including)
Fubarforum Chaozz 1.4 (including) 1.4 (including)
Fubarforum Chaozz 1.5 (including) 1.5 (including)

References