PT-2002-2860 · Mysimple · Mysimplenews

Published

2002-12-31

·

Updated

2008-09-05

·

CVE-2002-2143

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: MySimple News version 1.0
Description: The issue concerns the storage of the administrative password in plaintext within the admin.html file, allowing remote attackers to gain unauthorized access to the web server by viewing the source of the admin.html file.
Recommendations: For MySimple News version 1.0, consider modifying the admin.html file to store the administrative password securely, such as hashing and salting, to prevent unauthorized access. As a temporary workaround, restrict access to the admin.html file to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2002-2143

Affected Products

Mysimplenews