CVE-2006-0103

Severity CVSS v4.0:
Pending analysis
Type:
CWE-200 Information Leak / Disclosure
Publication date:
06/01/2006
Last modified:
03/04/2025

Description

TinyPHPForum 3.6 and earlier stores the (1) users/[USERNAME].hash and (2) users/[USERNAME].email files under the web root with insufficient access control, which allows remote attackers to list all registered users and possibly obtain other sensitive information.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ralph_capper:tinyphpforum:3.5:*:*:*:*:*:*:*
cpe:2.3:a:ralph_capper:tinyphpforum:3.6:*:*:*:*:*:*:*
cpe:2.3:a:ralph_capper:tinyphpforum:3.46:*:*:*:*:*:*:*
cpe:2.3:a:ralph_capper:tinyphpforum:3.47:*:*:*:*:*:*:*
cpe:2.3:a:ralph_capper:tinyphpforum:3.48:*:*:*:*:*:*:*
cpe:2.3:a:ralph_capper:tinyphpforum:3.49:*:*:*:*:*:*:*
cpe:2.3:a:ralph_capper:tinyphpforum:3.499:*:*:*:*:*:*:*