PT-2001-2007 · Ibill · Ibill Password Management System

Publicado

2001-11-22

·

Atualizado

2017-12-19

·

CVE-2001-0839

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions iBill password management system (affected versions not specified)
Description The issue concerns the generation of weak passwords by the ibillpm.pl script in the iBill password management system. These weak passwords are based on a client's MASTER ACCOUNT, making it possible for remote attackers to guess them through brute force methods. This could allow attackers to modify account information stored in the .htpasswd file.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2001-0839

Produtos afetados

Ibill Password Management System