{ "schema_version": "1.4.0", "id": "GHSA-vg4r-p8pw-h88f", "modified": "2022-05-01T18:20:44Z", "published": "2022-05-01T18:20:44Z", "aliases": [ "CVE-2007-4157" ], "details": "PHPBlogger stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing an admin password hash via a direct request for data/pref.db. NOTE: this can be easily leveraged for administrative access because composing the authentication cookie only requires the password hash, not the cleartext version.", "severity": [], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2007-4157" }, { "type": "WEB", "url": "http://forcehacker.com/forum/viewtopic.php?t=2352" }, { "type": "WEB", "url": "http://osvdb.org/38706" }, { "type": "WEB", "url": "http://osvdb.org/38707" }, { "type": "WEB", "url": "http://secunia.com/advisories/26262" }, { "type": "WEB", "url": "http://securityreason.com/securityalert/2957" }, { "type": "WEB", "url": "http://www.securityfocus.com/archive/1/474938/100/0/threaded" } ], "database_specific": { "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2007-08-03T21:17:00Z" } }