PT-2001-2007 · Ibill · Ibill Password Management System
Publicado
2001-11-22
·
Atualizado
2017-12-19
·
CVE-2001-0839
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
iBill password management system (affected versions not specified)
Description
The issue concerns the generation of weak passwords by the ibillpm.pl script in the iBill password management system. These weak passwords are based on a client's MASTER ACCOUNT, making it possible for remote attackers to guess them through brute force methods. This could allow attackers to modify account information stored in the .htpasswd file.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Ibill Password Management System