CVE-2002-0065
Summary
| CVE | CVE-2002-0065 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2002-04-22 04:00:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | Funk Software Proxy Host 3.x uses weak encryption for the Proxy Host password, which allows local users to gain privileges by recovering the passwords from the PHOST.INI file or the Windows registry. |
Risk And Classification
Primary CVSS: v2.0 7.2 from [email protected]
AV:L/AC:L/Au:N/C:C/I:C/A:C
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
LowAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:L/AC:L/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Bindview | Netrc | 1.0 | All | All | All |
| Application | Bindview | Netrc | 3.06 | All | All | All |
| Application | Funk Software | Funk Software Proxy | 3.0 | All | All | All |
| Application | Funk Software | Funk Software Proxy | 3.06 | All | All | All |
| Application | Funk Software | Funk Software Proxy | 3.09 | All | All | All |
| Application | Funk Software | Funk Software Proxy | 3.09a | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Razor: Security Advisories and Publications | af854a3a-2127-422b-91ae-364da2661108 | razor.bindview.com | Patch, Vendor Advisory |
| ISS X-Force Database: funk-proxy-weak-password (8792): Funk Software Proxy uses weak passwords | af854a3a-2127-422b-91ae-364da2661108 | www.iss.net | |
| Funk Software Proxy Weak Password Storage Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.