PT-2002-1930 · Cgiscript.Net · Cspassword.Cgi
Published
2002-08-31
·
Updated
2008-09-10
·
CVE-2002-0920
CVSS v2.0
5.1
Medium
| Vector | AV:N/AC:H/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
CGIScript.net csPassword.cgi (affected versions not specified)
Description:
The issue concerns the storage of sensitive data in a temporary file. Specifically, usernames and unencrypted passwords are stored in the password.cgi.tmp temporary file while data is being modified. This could potentially allow local users, and possibly remote attackers, to gain privileges by accessing the file before it has been processed.
Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cspassword.Cgi