CVE-2002-1800
7.5
CVSS Score
High
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Link copied!
Description
phpRank 1.8 stores the administrative password in plaintext on the server and in the "ap" cookie, which allows remote attackers to retrieve the administrative password.
CVSS Vector Details
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Affected Software Configurations
- a phprank phprank 1.8 * * * * * * *
Weaknesses (CWE)
- CWE-312
References & External Links
- http://archives.neohapsis.com/archives/bugtraq/2002-10/0148.html
- http://www.iss.net/security_center/static/10352.php
- http://www.securityfocus.com/bid/5947
- http://archives.neohapsis.com/archives/bugtraq/2002-10/0148.html
- http://www.iss.net/security_center/static/10352.php
- http://www.securityfocus.com/bid/5947
External Resources
CVE History Timeline
Jul 08, 2005 15:43
Initial Analysis
Feb 10, 2024 03:06
Reanalysis
May 14, 2024 01:22
CVE Modified
Nov 20, 2024 23:42
CVE Modified