PT-2004-2167 · Pafiledb · Pafiledb
Published
2004-12-15
·
Updated
2017-07-11
·
CVE-2004-1219
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
paFileDB version 3.1
Description:
The issue allows remote attackers to read the administrator's password hash and conduct brute force password guessing attacks by listing the contents of the sessions directory and reading the associated file for the administrator session, when sessions authentication is used and the administrator logs on.
Recommendations:
For paFileDB version 3.1, consider restricting access to the sessions directory to prevent unauthorized reading of the administrator's session file as a temporary workaround.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Pafiledb