PT-2003-1254 · 4D · Web Server 4D

Published

2003-04-02

·

Updated

2008-09-05

·

CVE-2002-1521

CVSS v2.0

2.1

Low

VectorAV:L/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Web Server 4D (WS4D) version 3.6
Description The issue allows attackers to gain privileges due to the storage of passwords in plaintext in the Ws4d.4DD file.
Recommendations For Web Server 4D (WS4D) version 3.6, consider encrypting or hashing passwords to prevent them from being stored in plaintext, and restrict access to the Ws4d.4DD file to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2002-1521

Affected Products

Web Server 4D