PT-2007-6468 · Atlassian · Stride

Durito

·

Publicado

2007-10-12

·

Atualizado

2018-10-15

·

CVE-2007-5432

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: Stride version 1.0
Description: The issue allows remote attackers to obtain administrative access due to a default administrator username and password. The default username is scott and the default password is running. This can be exploited through the "login.php" endpoint.
Recommendations: For Stride version 1.0, change the default administrator username and password to secure credentials as soon as possible to prevent unauthorized access. Consider temporarily restricting access to the "login.php" endpoint until the default credentials are changed.

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2007-5432

Produtos afetados

Stride