PT-2004-2405 · Unknown · Web Forums Server
R00Tcr4Ck
·
Publicado
2004-12-31
·
Atualizado
2016-10-18
·
CVE-2004-1497
CVSS v2.0
4.6
Média
| Vetor | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Web Forums Server versions 1.6 and 2.0 Power Pack
Description
The issue allows local users to gain privileges because passwords are stored in plaintext in the Username.ini file.
Recommendations
For Web Forums Server version 1.6, update the configuration to securely store passwords.
For Web Forums Server version 2.0 Power Pack, update the configuration to securely store passwords.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Web Forums Server