CVE-2006-6888
P-News 1.16 and 1.17 - Unauthenticated Sensitive Information Exposure via Direct Request
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-6888. PoCs published by 3l3ctric-Cracker.
AI-analyzed exploit summary This is a writeup describing an information disclosure vulnerability in P-News versions 1.16 and 1.17. The vulnerability allows remote attackers to access the user.dat file, which contains admin credentials in plaintext or hashed format.
Description
P-News 1.16 and 1.17 store sensitive information under the web root with insufficient access control, which allows remote attackers to obtain the administrative account name and password hash via a direct request for db/user.dat.
Exploits (1)
This is a writeup describing an information disclosure vulnerability in P-News versions 1.16 and 1.17. The vulnerability allows remote attackers to access the user.dat file, which contains admin credentials in plaintext or hashed format.