5

CVE-2004-2524

Exploit
clogin.php in Benchmark Designs' WHM AutoPilot 2.4.5 and earlier allows remote attackers to obtain plaintext username and password credentials by using the clogin_e and base64_encode functions to encode the desired user ID in the c parameter, then read the plaintext values in the resulting form.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Whm AutopilotWhm Autopilot Version2.4.5
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.72% 0.745
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://archives.neohapsis.com/archives/fulldisclosure/2004-07/1310.html
Vendor Advisory
http://secunia.com/advisories/12200
Patch
Vendor Advisory
http://securitytracker.com/id?1010833
Vendor Advisory
Exploit
http://www.osvdb.org/8279
http://www.securityfocus.com/bid/10846
https://exchange.xforce.ibmcloud.com/vulnerabilities/16849