Skip to content
Critical Published: Dec 31, 2001 Modified: Apr 03, 2025

CVE-2001-1481

9.8 CVSS Score Critical
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Export CVE-2001-1481 Data:
Share:
Link copied!

Description

Xitami 2.4 through 2.5 b4 stores the Administrator password in plaintext in the default.aut file, whose default permissions are world-readable, which allows remote attackers to gain privileges.

CVSS Vector Details

Attack Vector Network
Attack Complexity Low
Privileges Required None
User Interaction None
Scope Unchanged
Confidentiality High
Integrity High
Availability High

Affected Software Configurations

  • a xitami xitami * * * * * * * *
  • a xitami xitami 2.5 beta4 * * * * * *

Weaknesses (CWE)

  • CWE-312

CVE History Timeline

Aug 24, 2005 11:45 Initial Analysis
Jul 11, 2017 01:29 CVE Modified
Feb 13, 2024 16:20 Modified Analysis
May 14, 2024 01:20 CVE Modified
Nov 20, 2024 23:37 CVE Modified