vendor:
Wysi Wiki Wyg 1.0
by:
athos
7.5
CVSS
HIGH
Remote Password Retrieve
200
CWE
Product Name: Wysi Wiki Wyg 1.0
Affected Version From: 1
Affected Version To: 1
Patch Exists: Yes
Related CWE: N/A
CPE: a:wysiwyg:wysi_wiki_wyg
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2008
Wysi Wiki Wyg 1.0 Remote Password Retrieve Exploit
This exploit allows an attacker to retrieve the password of a Wysi Wiki Wyg 1.0 user by sending a malicious request to the server. The malicious request is sent to the /config/passwd.txt path, which contains the user's password in plaintext.
Mitigation:
Upgrade to the latest version of Wysi Wiki Wyg 1.0