PT-2005-4230 · Archilles · Archilles Newsworld

Chb

+1

·

Publicado

2005-11-02

·

Atualizado

2017-07-11

·

CVE-2005-3434

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Archilles Newsworld versions prior to 1.5.0-rc1
Description The issue allows remote attackers to obtain sensitive information, including usernames, hashed passwords, and session IDs, and potentially gain privileges due to insufficient access control of certain files stored under the web root.
Recommendations For versions prior to 1.5.0-rc1, update to version 1.5.0-rc1 or later to resolve the issue. As a temporary workaround, consider restricting access to the account.nwd and session.nwd files to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2005-3434

Produtos afetados

Archilles Newsworld