10
CVSSv2

CVE-2004-0621

Published: 06/12/2004 Updated: 11/07/2017
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

admin.php in Newsletter ZWS allows remote malicious users to gain administrative privileges via a list_user operation with the ulevel parameter set to 1 (administrator level), which lists all users and their passwords.

Vulnerable Product Search on Vulmon Subscribe to Product

zaireweb solutions newsletter zws

Exploits

source: wwwsecurityfocuscom/bid/10605/info Newsletter ZWS is reported prone to an administrative interface authentication bypass vulnerability The vulnerability exists due to a design error in the implementation of the authentication system for the interface The flaw allows a user to set their privileges through a URI parameter passed t ...