CVE Vulnerabilities

CVE-2009-1051

Published: Mar 24, 2009 | Modified: Nov 21, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

FubarForum 1.6 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing user credentials via a direct request for user.tsv.

Affected Software

Name Vendor Start Version End Version
Fubarforum Chaozz * 1.6 (including)
Fubarforum Chaozz 1.0 (including) 1.0 (including)
Fubarforum Chaozz 1.1 (including) 1.1 (including)
Fubarforum Chaozz 1.2 (including) 1.2 (including)
Fubarforum Chaozz 1.3 (including) 1.3 (including)
Fubarforum Chaozz 1.4 (including) 1.4 (including)
Fubarforum Chaozz 1.5 (including) 1.5 (including)

References