CVE-2002-1656 Information

Description

X-News (x_news) 1.1 and earlier allows attackers to authenticate as other users by obtaining the MD5 checksum of the password e.g. via sniffing or the users.txt data file and providing it in a cookie.

Reference

http://securitytracker.com/id?1003828 http://www.ifrance.com/kitetoua/tuto/x_holes.txt http://www.kb.cert.org/vuls/id/162723 http://www.securityfocus.com/bid/4283 https://exchange.xforce.ibmcloud.com/vulnerabilities/8465

Share on: