PT-2001-2612 · Easynews · Easynews
Published
2001-12-31
·
Updated
2009-04-03
·
CVE-2001-1527
CVSS v2.0
2.1
Low
| Vector | AV:L/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
easyNews versions 1.5 and earlier
Description
The issue allows local users to obtain administration passwords stored in cleartext in the settings.php file, potentially gaining access to the system.
Recommendations
For easyNews versions 1.5 and earlier, consider encrypting or hashing administration passwords stored in settings.php to prevent unauthorized access. As a temporary workaround, restrict access to the settings.php file to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Easynews