index.php in Flat PHP Board 1.2 and earlier allows remote authenticated users to obtain the password for the current user account by reading the password parameter value in the HTML source for the page generated by a profile action.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2007-12-17T18:00:00

Updated: 2018-10-15T20:57:01

Reserved: 2007-12-17T00:00:00


Link: CVE-2007-6399

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2007-12-17T18:46:00.000

Modified: 2018-10-15T21:52:55.987


Link: CVE-2007-6399

JSON object: View

cve-icon Redhat Information

No data.

CWE