CVE Vulnerabilities

CVE-2002-0310

Published: May 31, 2002 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Netwin WebNews 1.1k CGI program includes several default usernames and cleartext passwords that cannot be deleted by the administrator, which allows remote attackers to gain privileges via the username/password combinations (1) testweb/newstest, (2) alwn3845/imaptest, (3) alwi3845/wtest3452, or (4) testweb2/wtest4879.

Affected Software

NameVendorStart VersionEnd Version
WebnewsNetwin1.1h (including)1.1h (including)
WebnewsNetwin1.1i (including)1.1i (including)
WebnewsNetwin1.1j (including)1.1j (including)
WebnewsNetwin1.1k (including)1.1k (including)

References