CVE-2004-1724 describes an information disclosure vulnerability in PHP-Fusion 4.0, where the "ReadMe First.txt" file misguidedly instructs users to set world read/write/execute permissions (777) on the 'fusion_admin/db_backups' directory. This misconfiguration allows unauthenticated remote attackers to easily download or view database backup files, which contain sensitive administrator credentials due to predictable filenames. The vulnerability carries a CVSS score of 7.5, indicating high severity with low attack complexity and potential for partial confidentiality, integrity, and availability impact. While not listed on the KEV catalog, an ExploitDB entry (EDB-24384) confirms exploit code availability, though there is minimal community discussion or media coverage surrounding this older vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.0CPE matchmatch criteria | cpe:2.3:a:php_fusion:php_fusion:4.0:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.