PT-2005-4231 · Archilles · Archilles Newsworld

Chb

+1

·

Published

2005-11-02

·

Updated

2024-02-09

·

CVE-2005-3435

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Archilles Newsworld versions up to 1.3.0
Description The issue allows attackers to bypass authentication by obtaining the password hash for another user and specifying the hash in the pwd argument. This can be achieved, for example, through another Newsworld vulnerability.
Recommendations For Archilles Newsworld versions up to 1.3.0, update to a version later than 1.3.0 to resolve the issue. As a temporary workaround, consider restricting access to the admin news.php file to minimize the risk of exploitation. Avoid using the pwd argument in the admin news.php file until the issue is resolved.

Fix

Insufficiently Protected Credentials

Weakness Enumeration

Related Identifiers

CVE-2005-3435

Affected Products

Archilles Newsworld