PT-2002-1379 · Netwin · Netwin Webnews

Publicado

2002-05-03

·

Atualizado

2017-07-11

·

CVE-2002-0310

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Netwin WebNews version 1.1k
Description The issue concerns default usernames and cleartext passwords in the Netwin WebNews 1.1k CGI program. These default credentials, which include combinations such as testweb/newstest, alwn3845/imaptest, alwi3845/wtest3452, and testweb2/wtest4879, cannot be deleted by the administrator. This allows remote attackers to gain privileges by using these username/password combinations.
Recommendations For Netwin WebNews version 1.1k, consider changing the default usernames and passwords to custom, secure credentials to prevent unauthorized access. As a temporary workaround, restrict access to the CGI program until secure credentials can be implemented.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2002-0310

Produtos afetados

Netwin Webnews