PT-2001-2612 · Easynews · Easynews
Publicado
2001-12-31
·
Atualizado
2009-04-03
·
CVE-2001-1527
CVSS v2.0
2.1
Baixa
| Vetor | AV:L/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
easyNews versions 1.5 and earlier
Description
The issue allows local users to obtain administration passwords stored in cleartext in the settings.php file, potentially gaining access to the system.
Recommendations
For easyNews versions 1.5 and earlier, consider encrypting or hashing administration passwords stored in settings.php to prevent unauthorized access. As a temporary workaround, restrict access to the settings.php file to minimize the risk of exploitation.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Easynews