PT-2001-1323 · Phpweblog · Phpweblog

Published

2001-02-02

·

Updated

2017-12-19

·

CVE-2001-0088

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: phpWebLog version 0.4.2
Description: The issue arises from the improper initialization of the $CONF array in the common.inc.php file, which results in the password being set to a single character. This allows remote attackers to easily guess the SiteKey and gain administrative privileges.
Recommendations: For phpWebLog version 0.4.2, ensure proper initialization of the $CONF array to prevent the password from being set to a single character, thereby preventing remote attackers from guessing the SiteKey and gaining administrative privileges.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2001-0088

Affected Products

Phpweblog