SimplePHPBlog 0.4.0 stores password hashes in config/password.txt with insufficient access control, which allows remote attackers to obtain passwords via a brute force attack.
Software | From | Fixed in |
---|---|---|
alexander_palmo / simple_php_blog | 0.4.0 | 0.4.0.x |