7.5
CVSSv2

CVE-2000-0589

Published: 26/06/2000 Updated: 30/07/2013
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SawMill 5.0.21 uses weak encryption to store passwords, which allows malicious users to easily decrypt the password and modify the SawMill configuration.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

sawmill sawmill 5.0.21

Exploits

source: wwwsecurityfocuscom/bid/1403/info Sawmill is a site statistics package for Unix, Windows and Mac OS Passwords are encrypted using a weak hash function This combined with the file disclosure vulnerability in Sawmill (bid = 1402) could allow an attacker to read the contents of sawmill's password file, then decrypt the password and ...