PT-2001-2620 · Slashcode · Slashcode
Publicado
2001-12-31
·
Atualizado
2008-09-05
·
CVE-2001-1535
CVSS v2.0
4.6
Média
| Vetor | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Slashcode version 2.0
Description
The issue allows local users to potentially gain unauthorized access via a brute force attack, as the software creates new accounts with 8-character random passwords, which could be cracked to obtain session IDs from cookies.
Recommendations
For Slashcode version 2.0, consider implementing stronger password generation to minimize the risk of brute force attacks, and restrict access to sensitive areas of the application until a more secure authentication mechanism is in place.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Slashcode