PT-2005-4230 · Archilles · Archilles Newsworld

Chb

+1

·

Published

2005-11-02

·

Updated

2017-07-11

·

CVE-2005-3434

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Archilles Newsworld versions prior to 1.5.0-rc1
Description The issue allows remote attackers to obtain sensitive information, including usernames, hashed passwords, and session IDs, and potentially gain privileges due to insufficient access control of certain files stored under the web root.
Recommendations For versions prior to 1.5.0-rc1, update to version 1.5.0-rc1 or later to resolve the issue. As a temporary workaround, consider restricting access to the account.nwd and session.nwd files to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-3434

Affected Products

Archilles Newsworld