PT-2003-1254 · 4D · Web Server 4D
Published
2003-04-02
·
Updated
2008-09-05
·
CVE-2002-1521
CVSS v2.0
2.1
Low
| Vector | AV:L/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Web Server 4D (WS4D) version 3.6
Description
The issue allows attackers to gain privileges due to the storage of passwords in plaintext in the Ws4d.4DD file.
Recommendations
For Web Server 4D (WS4D) version 3.6, consider encrypting or hashing passwords to prevent them from being stored in plaintext, and restrict access to the Ws4d.4DD file to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Web Server 4D