CVE-2003-1540

Severity CVSS v4.0:
Pending analysis
Type:
CWE-200 Information Leak / Disclosure
Publication date:
31/12/2003
Last modified:
03/04/2025

Description

WF-Chat 1.0 Beta stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain authentication information via a direct request to (1) !pwds.txt and (2) !nicks.txt.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:wfchat:wfchat:1.0:beta:*:*:*:*:*:*