CVE detail
CVE-2007-4157 — CVE-2007-4157
Published 2007-08-03 · Modified 2026-06-16 · Vendor phpblogger · Product php-blogger · Source nvd
UNKNOWN
severity
CVSS-derived band
0.0231
EPSS probability
exploitation probability, 30d
82.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
PHPBlogger stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing an admin password hash via a direct request for data/pref.db. NOTE: this can be easily leveraged for administrative access because composing the authentication cookie only requires the password hash, not the cleartext version.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References