PT-2004-2405 · Unknown · Web Forums Server
R00Tcr4Ck
·
Published
2004-12-31
·
Updated
2016-10-18
·
CVE-2004-1497
CVSS v2.0
4.6
Medium
| Vector | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Web Forums Server versions 1.6 and 2.0 Power Pack
Description
The issue allows local users to gain privileges because passwords are stored in plaintext in the Username.ini file.
Recommendations
For Web Forums Server version 1.6, update the configuration to securely store passwords.
For Web Forums Server version 2.0 Power Pack, update the configuration to securely store passwords.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Web Forums Server