PT-2002-1379 · Netwin · Netwin Webnews
Publicado
2002-05-03
·
Atualizado
2017-07-11
·
CVE-2002-0310
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Netwin WebNews version 1.1k
Description
The issue concerns default usernames and cleartext passwords in the Netwin WebNews 1.1k CGI program. These default credentials, which include combinations such as
testweb/newstest, alwn3845/imaptest, alwi3845/wtest3452, and testweb2/wtest4879, cannot be deleted by the administrator. This allows remote attackers to gain privileges by using these username/password combinations.Recommendations
For Netwin WebNews version 1.1k, consider changing the default usernames and passwords to custom, secure credentials to prevent unauthorized access. As a temporary workaround, restrict access to the CGI program until secure credentials can be implemented.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Netwin Webnews