PT-2004-2167 · Pafiledb · Pafiledb

Published

2004-12-15

·

Updated

2017-07-11

·

CVE-2004-1219

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions: paFileDB version 3.1
Description: The issue allows remote attackers to read the administrator's password hash and conduct brute force password guessing attacks by listing the contents of the sessions directory and reading the associated file for the administrator session, when sessions authentication is used and the administrator logs on.
Recommendations: For paFileDB version 3.1, consider restricting access to the sessions directory to prevent unauthorized reading of the administrator's session file as a temporary workaround.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2004-1219

Affected Products

Pafiledb