The admin.html file in StepWeb Search Engine (SWS) 2.5 stores passwords in links to manager.pl, which allows remote attackers who can access the admin.html file to gain administrative privileges to SWS.
References
Link | Resource |
---|---|
http://archives.neohapsis.com/archives/bugtraq/2002-04/0148.html | Exploit Patch Vendor Advisory |
http://www.iss.net/security_center/static/8849.php | Vendor Advisory |
http://www.securityfocus.com/bid/4503 | Patch Vendor Advisory |
http://archives.neohapsis.com/archives/bugtraq/2002-04/0148.html | Exploit Patch Vendor Advisory |
http://www.iss.net/security_center/static/8849.php | Vendor Advisory |
http://www.securityfocus.com/bid/4503 | Patch Vendor Advisory |
Configurations
History
20 Nov 2024, 23:39
Type | Values Removed | Values Added |
---|---|---|
References | () http://archives.neohapsis.com/archives/bugtraq/2002-04/0148.html - Exploit, Patch, Vendor Advisory | |
References | () http://www.iss.net/security_center/static/8849.php - Vendor Advisory | |
References | () http://www.securityfocus.com/bid/4503 - Patch, Vendor Advisory |
Information
Published : 2002-07-03 04:00
Updated : 2024-11-20 23:39
NVD link : CVE-2002-0537
Mitre link : CVE-2002-0537
CVE.ORG link : CVE-2002-0537
JSON object : View
Products Affected
stepweb
- sws
CWE