X-News (x_news) 1.1 and earlier allows attackers to authenticate as other users by obtaining the MD5 checksum of the password, e.g. via sniffing or the users.txt data file, and providing it in a cookie.
References
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2002-12-31 05:00
Updated : 2024-02-04 16:31
NVD link : CVE-2002-1656
Mitre link : CVE-2002-1656
CVE.ORG link : CVE-2002-1656
JSON object : View
Products Affected
xqus
- x-news
CWE