PT-2002-2860 · Mysimple · Mysimplenews
Published
2002-12-31
·
Updated
2008-09-05
·
CVE-2002-2143
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
MySimple News version 1.0
Description:
The issue concerns the storage of the administrative password in plaintext within the admin.html file, allowing remote attackers to gain unauthorized access to the web server by viewing the source of the admin.html file.
Recommendations:
For MySimple News version 1.0, consider modifying the admin.html file to store the administrative password securely, such as hashing and salting, to prevent unauthorized access. As a temporary workaround, restrict access to the admin.html file to minimize the risk of exploitation.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mysimplenews