The admin.html file in StepWeb Search Engine (SWS) 2.5 stores passwords in links to manager.pl, which allows remote attackers who can access the admin.html file to gain administrative privileges to SWS.
References
Link | Resource |
---|---|
http://archives.neohapsis.com/archives/bugtraq/2002-04/0148.html | Exploit Patch Vendor Advisory |
http://www.iss.net/security_center/static/8849.php | Vendor Advisory |
http://www.securityfocus.com/bid/4503 | Patch Vendor Advisory |
Configurations
Information
Published : 2002-07-02 21:00
Updated : 2008-09-05 13:28
NVD link : CVE-2002-0537
Mitre link : CVE-2002-0537
JSON object : View
CWE
Products Affected
stepweb
- sws