CVE-2007-6399

Severity CVSS v4.0:
Pending analysis
Type:
CWE-255 Credentials Management
Publication date:
17/12/2007
Last modified:
09/04/2025

Description

index.php in Flat PHP Board 1.2 and earlier allows remote authenticated users to obtain the password for the current user account by reading the password parameter value in the HTML source for the page generated by a profile action.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:myupb:flat_php_board:*:*:*:*:*:*:*:* 1.2 (including)