PT-2004-2405 · Unknown · Web Forums Server

R00Tcr4Ck

·

Published

2004-12-31

·

Updated

2016-10-18

·

CVE-2004-1497

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Web Forums Server versions 1.6 and 2.0 Power Pack
Description The issue allows local users to gain privileges because passwords are stored in plaintext in the Username.ini file.
Recommendations For Web Forums Server version 1.6, update the configuration to securely store passwords. For Web Forums Server version 2.0 Power Pack, update the configuration to securely store passwords.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2004-1497

Affected Products

Web Forums Server