First published: Mon Jun 20 2005(Updated: )
paFAQ 1.0 Beta 4 allows remote attackers to obtain sensitive information via a direct request to admin/backup.php, which contains a backup of the database including usernames and passwords.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Php Arena Pafaq | =1.0_beta_4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-2013 is classified as a high severity vulnerability due to the exposure of sensitive information.
To fix CVE-2005-2013, ensure that the admin/backup.php file is properly protected or restricted from direct access.
CVE-2005-2013 exposes sensitive information such as usernames and passwords stored in the database backup.
CVE-2005-2013 affects Php Arena Pafaq version 1.0 Beta 4.
Yes, CVE-2005-2013 can be exploited remotely, allowing attackers to access the backup file without authorization.