SimpleBBS 1.0.6 - 'users.php' Insecure File Permissions
Author: flur
type: webapps
platform: php
port:
date_added: 2003-03-07
date_updated: 2012-10-30
verified: 1
codes: OSVDB-7045
tags:
aliases:
screenshot_url:
application_url:
source: https://www.securityfocus.com/bid/7045/info
SimpleBBS reportedly creates sensitive files with world-readable permissions.
As a result anyone who has access to SimpleBBS web resources may access confidential information stored in the SimpleBBS user database.
This vulnerability was reported for SimpleBBS 1.0.6. It is not known if earlier versions are affected by this vulnerability.
http://www.example.com/simplebbs/users/users.php