Haakon Nilsen · Haakon Nilsen Simple Internet Publishing System · CVE-2003-1553
**Name of the Vulnerable Software and Affected Versions**
Haakon Nilsen Simple Internet Publishing System (SIPS) version 0.2.2
**Description**
The issue allows remote attackers to obtain password and other user information due to insufficient access control of sensitive information stored under the web root. This can be achieved via a direct request to a user-specific configuration directory.
**Recommendations**
For Haakon Nilsen Simple Internet Publishing System (SIPS) version 0.2.2, consider restricting access to user-specific configuration directories to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.