Field Assessment
AI analysis pending.
CVE
CVE-2006-0103
Severity
MEDIUM
CVSS
5
EPSS
4.08%
Original Filing — NVD Description
TinyPHPForum 3.6 and earlier stores the (1) users/[USERNAME].hash and (2) users/[USERNAME].email files under the web root with insufficient access control, which allows remote attackers to list all registered users and possibly obtain other sensitive information.