PT-2001-2620 · Slashcode · Slashcode

Published

2001-12-31

·

Updated

2008-09-05

·

CVE-2001-1535

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Slashcode version 2.0
Description The issue allows local users to potentially gain unauthorized access via a brute force attack, as the software creates new accounts with 8-character random passwords, which could be cracked to obtain session IDs from cookies.
Recommendations For Slashcode version 2.0, consider implementing stronger password generation to minimize the risk of brute force attacks, and restrict access to sensitive areas of the application until a more secure authentication mechanism is in place.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2001-1535

Affected Products

Slashcode