vendor:
P-News
by:
Dr Max Virus
9
CVSS
CRITICAL
Remote Password Disclosure
N/A
CWE
Product Name: P-News
Affected Version From: 1.16
Affected Version To: 1.17
Patch Exists: N/A
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
N/A
P-News (user.dat)Remote Password Disclosure Vulnerability
P-News versions 1.17 and 1.16 are vulnerable to a remote password disclosure vulnerability. An attacker can access the user.dat file located at http:/[target]/[path]/db/user.dat to view the admin name and hash. The password can be cracked with any md5 encrypt or injected into a cookie editor such as FireFox or Opera.
Mitigation:
Ensure that the user.dat file is not accessible to unauthorized users.