7.5
CVSSv2

CVE-2002-1656

Published: 31/12/2002 Updated: 11/07/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

X-News (x_news) 1.1 and previous versions allows malicious users to authenticate as other users by obtaining the MD5 checksum of the password, e.g. via sniffing or the users.txt data file, and providing it in a cookie.

Vulnerable Product Search on Vulmon Subscribe to Product

xqus x-news 1.1

xqus x-news 1.0

Exploits

x-news 11 Password Disclosure Vulnerability Affected Software: x-news 11 x-news Website: xquscom Bugfounder: bd0rk Website: wwwsoh-crewittt Contact: bd0rk[at]hackermailcom Greetings: str0ke, Perle, TheJT, ajann [+]Exploit: [target]/[x_news_path]/news/db/userstxt Showexample: |username|MD5-Ha ...