PT-2004-3608 · Phpmychat · Phpmychat
Published
2004-12-31
·
Updated
2008-09-05
·
CVE-2004-2718
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
PHPMyChat version 0.14.5
Description
The issue allows attackers to obtain sensitive information, including database passwords, by directly requesting the setup.php3 file, which is not removed or protected after installation.
Recommendations
For PHPMyChat version 0.14.5, remove or protect the setup.php3 file after installation to prevent unauthorized access.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Phpmychat