Vulnerability Description
PHPMyChat 0.14.5 does not remove or protect setup.php3 after installation, which allows attackers to obtain sensitive information including database passwords via a direct request.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Php Heaven | Phpmychat | 0.14.5 |
Related Weaknesses (CWE)
References
- http://secunia.com/advisories/11894Vendor Advisory
- http://www.securiteam.com/unixfocus/6D00S0KC0S.html
- http://secunia.com/advisories/11894Vendor Advisory
- http://www.securiteam.com/unixfocus/6D00S0KC0S.html
FAQ
What is CVE-2004-2718?
CVE-2004-2718 is a vulnerability with a CVSS score of 4.3 (MEDIUM). PHPMyChat 0.14.5 does not remove or protect setup.php3 after installation, which allows attackers to obtain sensitive information including database passwords via a direct request.
How severe is CVE-2004-2718?
CVE-2004-2718 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2004-2718?
Check the references section above for vendor advisories and patch information. Affected products include: Php Heaven Phpmychat.