PT-2004-3608 · Phpmychat · Phpmychat

Published

2004-12-31

·

Updated

2008-09-05

·

CVE-2004-2718

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions PHPMyChat version 0.14.5
Description The issue allows attackers to obtain sensitive information, including database passwords, by directly requesting the setup.php3 file, which is not removed or protected after installation.
Recommendations For PHPMyChat version 0.14.5, remove or protect the setup.php3 file after installation to prevent unauthorized access.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2004-2718

Affected Products

Phpmychat