It is reported that PvPGN is susceptible to an information disclosure vulnerability. This vulnerability allows an attacker to request information about any arbitrary user contained in the server. The information that an attacker can retrieve includes password hashes, which allows an attacker to gain access to any account. Versions prior to 1.6.4, or CVS users dated before 2004-08-23 are reported vulnerable to this issue.
It is reported that PvPGN is susceptible to an information disclosure vulnerability. This vulnerability allows an attacker to request information about any arbitrary user contained in the server. The information that an attacker can retrieve includes password hashes, which allows an attacker to gain access to any account. Versions prior to 1.6.4, or CVS users dated before 2004-08-23 are reported vulnerable to this issue.