VendorsMariovaldezsimple_text-file_login_script1.0.6
Vulnerabilities

Mariovaldez Simple Text-file Login Script 1.0.6

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2008-5763
PHP remote file inclusion vulnerability in slogin_lib.inc.php in Simple Text-File Login Script (SiTeFiLo) 1.0.6 allows remote attackers to execute arbitrary PHP code via a URL in the slogin_path parameter.
Published 2008-12-30 · Modified
7.51 PoCEPSS 0.392
CVE-2008-5762
Simple Text-File Login Script (SiTeFiLo) 1.0.6 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing the password via a direct request for slog_users.txt.
Published 2008-12-30 · Modified
5.01 PoCEPSS 0.026