PHP Message Board/Guestbook

From: subj (r2subj3ctat_private)
Date: Mon Mar 17 2003 - 16:45:08 PST

  • Next message: Brett Moore: "RE: Microsoft Security Advisory MS 03-007"

    
     ('binary' encoding is not supported, stored as-is)
    Product : PHP Message Board/Guestbook
    Version : First
    WebSite : http://www.cyber-cats.com/php
    Problem : Viewing passwords file
    
    Description:
    ------------
    
    In this script passwords are in passwd.txt file
    They are encrypted by DES algorithm.
    In Shrot, all who want see the passwords can make it.
    
    Exploit:
    --------
    
    http://[somehost]/[gb_dir]/files/passwd.txt
    



    This archive was generated by hypermail 2b30 : Tue Mar 18 2003 - 16:33:14 PST