PT-2001-2007 · Ibill · Ibill Password Management System

Published

2001-11-22

·

Updated

2017-12-19

·

CVE-2001-0839

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions iBill password management system (affected versions not specified)
Description The issue concerns the generation of weak passwords by the ibillpm.pl script in the iBill password management system. These weak passwords are based on a client's MASTER ACCOUNT, making it possible for remote attackers to guess them through brute force methods. This could allow attackers to modify account information stored in the .htpasswd file.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2001-0839

Affected Products

Ibill Password Management System