Loading...
Loading...
PHPBlogger stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing an admin password hash via a direct request for data/pref.db. NOTE: this can be easily leveraged for administrative access because composing the authentication cookie only requires the password hash, not the cleartext version.
August 3, 2007
April 23, 2026
See which npm, PyPI, Go, and Maven packages are affected by CVE-2007-4157
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.