CVE-2001-1537
7.5
CVSS Score
High
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Link copied!
Description
The default "basic" security setting' in config.php for TWIG webmail 2.7.4 and earlier stores cleartext usernames and passwords in cookies, which could allow attackers to obtain authentication information and gain privileges.
CVSS Vector Details
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Affected Software Configurations
- a symfony twig * * * * * * * *
Weaknesses (CWE)
- CWE-312
References & External Links
- http://archives.neohapsis.com/archives/bugtraq/2001-11/0245.html
- http://www.iss.net/security_center/static/7619.php
- http://www.securityfocus.com/bid/3591
- http://archives.neohapsis.com/archives/bugtraq/2001-11/0245.html
- http://www.iss.net/security_center/static/7619.php
- http://www.securityfocus.com/bid/3591
External Resources
CVE History Timeline
Sep 26, 2005 20:36
Initial Analysis
Feb 13, 2024 16:19
Reanalysis
May 14, 2024 01:20
CVE Modified
Nov 20, 2024 23:37
CVE Modified