CVE Vulnerabilities

CVE-2002-0706

Published: Oct 10, 2002 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

UserManager.js in the Web Reports Server for SurfControl SuperScout WebFilter uses weak encryption for administrator functions, which allows remote attackers to decrypt the administrative password using a hard-coded key in a Javascript function.

Affected Software

NameVendorStart VersionEnd Version
Superscout_web_filterSurfcontrol3.0 (including)3.0 (including)
Superscout_web_filterSurfcontrol3.0.3 (including)3.0.3 (including)
Web_filterSurfcontrol4.0 (including)4.0 (including)
Web_filterSurfcontrol4.1 (including)4.1 (including)

References