CVE Vulnerabilities

CVE-2002-0310

Published: May 31, 2002 | Modified: Jul 11, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Netwin WebNews 1.1k CGI program includes several default usernames and cleartext passwords that cannot be deleted by the administrator, which allows remote attackers to gain privileges via the username/password combinations (1) testweb/newstest, (2) alwn3845/imaptest, (3) alwi3845/wtest3452, or (4) testweb2/wtest4879.

Affected Software

Name Vendor Start Version End Version
Webnews Netwin 1.1h (including) 1.1h (including)
Webnews Netwin 1.1i (including) 1.1i (including)
Webnews Netwin 1.1j (including) 1.1j (including)
Webnews Netwin 1.1k (including) 1.1k (including)

References