[原文]PHP Upload Center stores password hashes under the web root with insufficient access control, which allows remote attackers to download each password hash via a direct request for the upload/users/[USERNAME] file.
PHP Upload Center Direct Request User Password Hash Disclosure
Remote / Network Access
Loss of Confidentiality
PHP Upload Center contains a flaw that may lead to an unauthorized password exposure. It is possible to gain access to hashed passwords from an HTTP request like http://[site]/[path]/users/[user], which may lead to a loss of confidentiality.
Currently, there are no known upgrades, patches, or workarounds available to correct this issue.