CVE-2005-3049: Medium severity PhpMyFaq phpmyfaq vulnerability
Published Sep 23, 2005
·Updated
PhpMyFaq 1.5.1 stores data files under the web document root with insufficient access control and predictable filenames, which allows remote attackers to obtain sensitive information via a direct request to the data/tracking[DATE] file.
Affected Software
1 affected component
PhpMyFaq phpmyfaq=1.5.1
Event History
Sep 23, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-3049?
CVE-2005-3049 is considered a medium-severity vulnerability due to its potential impact on sensitive data exposure.
2
How do I fix CVE-2005-3049?
To fix CVE-2005-3049, ensure that the data files are moved outside the web document root and apply proper access controls.
3
What types of attacks are possible due to CVE-2005-3049?
CVE-2005-3049 allows attackers to access sensitive information by directly requesting the data/tracking files.
4
Which version of PhpMyFaq is affected by CVE-2005-3049?
CVE-2005-3049 specifically affects PhpMyFaq version 1.5.1.
5
Can CVE-2005-3049 lead to data theft?
Yes, CVE-2005-3049 can lead to data theft as it allows unauthorized access to sensitive tracking data.