VULNERABILITY INTELLIGENCE

CVE-2003-1540

CVSS score5 MEDIUM
EPSS probability3.23%
CISA KEVNot currently listed
Published2003-12-31
Last modified2026-06-16
CVSS vectorAV:N/AC:L/Au:N/C:P/I:N/A:N

Description

WF-Chat 1.0 Beta stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain authentication information via a direct request to (1) !pwds.txt and (2) !nicks.txt.

Weakness classification

  • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor

Primary references