PT-2007-3873 · Mysql Server+1 · Mysql Server+1
Published
2007-05-09
·
Updated
2018-10-16
·
CVE-2007-2554
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:C/A:N |
Name of the Vulnerable Software and Affected Versions
AP Newspower versions 4.0.1 and earlier
Description
The issue allows remote attackers to insert or modify news articles via the
shows.tblscript due to a default blank password for the MySQL root account.Recommendations
For AP Newspower versions 4.0.1 and earlier, change the default blank password for the MySQL root account to a secure password to prevent unauthorized access.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ap Newspower
Mysql Server