Description
SimplePHPBlog 0.4.0 stores password hashes in config/password.txt with insufficient access control, which allows remote attackers to obtain passwords via a brute force attack.
Affected products
- alexander_palmo / simple_php_blog0.4.0 – 0.4.0
References
- VENDOR_ADVISORYhttp://secunia.com/advisories/15954
- MAILING_LISThttp://marc.info/?l=bugtraq&m=112075901100640&w=2