PT-2001-1591 · Akopia · Akopia Interchange

Published

2001-05-24

·

Updated

2017-12-19

·

CVE-2001-0372

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Akopia Interchange versions 4.5.3 through 4.6.3
Description The issue allows a remote attacker to gain administrative access due to demo stores being installed with a default group account :backup that has no password. This can be exploited via the demo stores, including (1) barry, (2) basic, or (3) construct.
Recommendations For versions 4.5.3 through 4.6.3, change the password of the :backup group account to prevent unauthorized access. Consider removing or securing the demo stores (barry, basic, construct) until a proper fix is applied.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2001-0372

Affected Products

Akopia Interchange