CVE-2004-2718

PHP Heaven Phpmychat - Access Control

Title source: rule
STIX 2.1

Description

PHPMyChat 0.14.5 does not remove or protect setup.php3 after installation, which allows attackers to obtain sensitive information including database passwords via a direct request.

Exploits (1)

exploitdb WORKING POC VERIFIED
by sysbug · perlwebappsphp
https://www.exploit-db.com/exploits/703

Scores

EPSS 0.0284
EPSS Percentile 86.2%

Details

CWE
CWE-264
Status published
Products (1)
php_heaven/phpmychat 0.14.5
Published Dec 31, 2004
Tracked Since Feb 18, 2026