CVE-2006-1209 EXPLOIT
5.0
MEDIUM · CVSS 2.0 · EPSS 3.4% (pctl 88)
Patch early
A public exploit exists.
Description
PHP Advanced Transfer Manager 1.00 through 1.30 stores sensitive information, including password hashes, under the web root with insufficient access control, which allows remote attackers to download each password hash via a direct request for a users/[USERNAME] file.
Scoring
| CVSS | 5.0 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
| EPSS | 3.39% — more likely to be exploited than 88% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2006-03-14 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| bugada andrea | php advanced transfer manager |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | PHP Advanced Transfer Manager 1.30 - Source Code Disclosure | 2006-12-20 |
References
- http://biyosecurity.be/bugs/patm.txt
- http://secunia.com/advisories/17134
- http://securityreason.com/securityalert/565
- http://www.blogcu.com/Liz0ziM/316652/
- http://www.securityfocus.com/archive/1/427216/100/0/threaded
- http://www.securityfocus.com/archive/1/437513/100/200/threaded
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25127
- http://biyosecurity.be/bugs/patm.txt
- http://secunia.com/advisories/17134
- http://securityreason.com/securityalert/565
- http://www.blogcu.com/Liz0ziM/316652/
- http://www.securityfocus.com/archive/1/427216/100/0/threaded
- http://www.securityfocus.com/archive/1/437513/100/200/threaded
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25127
→ the Explorer · watch your stack · NVD