PT-2001-1323 · Phpweblog · Phpweblog

Publicado

2001-02-02

·

Atualizado

2017-12-19

·

CVE-2001-0088

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: phpWebLog version 0.4.2
Description: The issue arises from the improper initialization of the $CONF array in the common.inc.php file, which results in the password being set to a single character. This allows remote attackers to easily guess the SiteKey and gain administrative privileges.
Recommendations: For phpWebLog version 0.4.2, ensure proper initialization of the $CONF array to prevent the password from being set to a single character, thereby preventing remote attackers from guessing the SiteKey and gaining administrative privileges.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2001-0088

Produtos afetados

Phpweblog