PT-2002-2860 · Mysimple · Mysimplenews
Publicado
2002-12-31
·
Atualizado
2008-09-05
·
CVE-2002-2143
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
MySimple News version 1.0
Description:
The issue concerns the storage of the administrative password in plaintext within the admin.html file, allowing remote attackers to gain unauthorized access to the web server by viewing the source of the admin.html file.
Recommendations:
For MySimple News version 1.0, consider modifying the admin.html file to store the administrative password securely, such as hashing and salting, to prevent unauthorized access. As a temporary workaround, restrict access to the admin.html file to minimize the risk of exploitation.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Mysimplenews