PT-2001-2620 · Slashcode · Slashcode
Published
2001-12-31
·
Updated
2008-09-05
·
CVE-2001-1535
CVSS v2.0
4.6
Medium
| Vector | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Slashcode version 2.0
Description
The issue allows local users to potentially gain unauthorized access via a brute force attack, as the software creates new accounts with 8-character random passwords, which could be cracked to obtain session IDs from cookies.
Recommendations
For Slashcode version 2.0, consider implementing stronger password generation to minimize the risk of brute force attacks, and restrict access to sensitive areas of the application until a more secure authentication mechanism is in place.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Slashcode