CVE-2006-0370

Noah Medling RCBlog 1.03 stores the data and config directories under the web root with insufficient access control, which allows remote attackers to view account names and MD5 password hashes.
Configurations

Configuration 1 (hide)

cpe:2.3:a:noah_medling:rcblog:1.03:*:*:*:*:*:*:*

History

21 Nov 2024, 00:06

Type Values Removed Values Added
References () http://evuln.com/vulns/42/summary.html - Exploit, Vendor Advisory () http://evuln.com/vulns/42/summary.html - Exploit, Vendor Advisory
References () http://secunia.com/advisories/18547 - Vendor Advisory () http://secunia.com/advisories/18547 - Vendor Advisory
References () http://securitytracker.com/id?1015523 - () http://securitytracker.com/id?1015523 -
References () http://www.fluffington.com/index.php?page=rcblog - URL Repurposed () http://www.fluffington.com/index.php?page=rcblog - URL Repurposed
References () http://www.osvdb.org/22679 - () http://www.osvdb.org/22679 -
References () http://www.securityfocus.com/archive/1/422499/100/0/threaded - () http://www.securityfocus.com/archive/1/422499/100/0/threaded -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/24249 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/24249 -

14 Feb 2024, 01:17

Type Values Removed Values Added
References () http://www.fluffington.com/index.php?page=rcblog - () http://www.fluffington.com/index.php?page=rcblog - URL Repurposed

Information

Published : 2006-01-22 20:03

Updated : 2025-04-03 01:03


NVD link : CVE-2006-0370

Mitre link : CVE-2006-0370

CVE.ORG link : CVE-2006-0370


JSON object : View

Products Affected

noah_medling

  • rcblog