{"api_version":"1","generated_at":"2026-07-23T05:35:28+00:00","cve":"CVE-2002-0065","urls":{"html":"https://cve.report/CVE-2002-0065","api":"https://cve.report/api/cve/CVE-2002-0065.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2002-0065","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2002-0065"},"summary":{"title":"CVE-2002-0065","description":"Funk Software Proxy Host 3.x uses weak encryption for the Proxy Host password, which allows local users to gain privileges by recovering the passwords from the PHOST.INI file or the Windows registry.","state":"PUBLISHED","assigner":"mitre","published_at":"2002-04-22 04:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.2","severity":"","vector":"AV:L/AC:L/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:C/I:C/A:C","baseScore":7.2,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://razor.bindview.com/publish/advisories/adv_FunkProxy.html","name":"http://razor.bindview.com/publish/advisories/adv_FunkProxy.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"Razor: Security Advisories and Publications","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://www.iss.net/security_center/static/8792.php","name":"http://www.iss.net/security_center/static/8792.php","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"ISS X-Force Database: funk-proxy-weak-password (8792): Funk Software Proxy uses weak passwords","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/4459","name":"http://www.securityfocus.com/bid/4459","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Funk Software Proxy Weak Password Storage Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2002-0065","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2002-0065","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2002","cve_id":"65","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"bindview","cpe5":"netrc","cpe6":"1.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2002","cve_id":"65","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"bindview","cpe5":"netrc","cpe6":"3.06","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2002","cve_id":"65","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"funk_software","cpe5":"funk_software_proxy","cpe6":"3.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2002","cve_id":"65","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"funk_software","cpe5":"funk_software_proxy","cpe6":"3.06","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2002","cve_id":"65","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"funk_software","cpe5":"funk_software_proxy","cpe6":"3.09","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2002","cve_id":"65","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"funk_software","cpe5":"funk_software_proxy","cpe6":"3.09a","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-08T02:35:17.410Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"funk-proxy-weak-password(8792)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"http://www.iss.net/security_center/static/8792.php"},{"name":"4459","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/4459"},{"name":"20020408 Unauthorized remote control access to systems running Funk Software's Proxy v3.x","tags":["vendor-advisory","x_refsource_BINDVIEW","x_transferred"],"url":"http://razor.bindview.com/publish/advisories/adv_FunkProxy.html"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2002-04-08T00:00:00.000Z","descriptions":[{"lang":"en","value":"Funk Software Proxy Host 3.x uses weak encryption for the Proxy Host password, which allows local users to gain privileges by recovering the passwords from the PHOST.INI file or the Windows registry."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2002-06-16T00:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"funk-proxy-weak-password(8792)","tags":["vdb-entry","x_refsource_XF"],"url":"http://www.iss.net/security_center/static/8792.php"},{"name":"4459","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/4459"},{"name":"20020408 Unauthorized remote control access to systems running Funk Software's Proxy v3.x","tags":["vendor-advisory","x_refsource_BINDVIEW"],"url":"http://razor.bindview.com/publish/advisories/adv_FunkProxy.html"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2002-0065","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Funk Software Proxy Host 3.x uses weak encryption for the Proxy Host password, which allows local users to gain privileges by recovering the passwords from the PHOST.INI file or the Windows registry."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"funk-proxy-weak-password(8792)","refsource":"XF","url":"http://www.iss.net/security_center/static/8792.php"},{"name":"4459","refsource":"BID","url":"http://www.securityfocus.com/bid/4459"},{"name":"20020408 Unauthorized remote control access to systems running Funk Software's Proxy v3.x","refsource":"BINDVIEW","url":"http://razor.bindview.com/publish/advisories/adv_FunkProxy.html"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2002-0065","datePublished":"2002-06-25T04:00:00.000Z","dateReserved":"2002-02-19T00:00:00.000Z","dateUpdated":"2024-08-08T02:35:17.410Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2002-04-22 04:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:C/I:C/A:C","baseScore":7.2,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":3.9,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":true,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:bindview:netrc:1.0:*:*:*:*:*:*:*","matchCriteriaId":"760DB974-6B4A-4A09-9B4F-201456DE9136"},{"vulnerable":true,"criteria":"cpe:2.3:a:bindview:netrc:3.06:*:*:*:*:*:*:*","matchCriteriaId":"AD26D34A-F8C0-4C74-A825-6B59DA0C12D8"},{"vulnerable":true,"criteria":"cpe:2.3:a:funk_software:funk_software_proxy:3.0:*:*:*:*:*:*:*","matchCriteriaId":"8ECA01B9-A163-4069-8CBA-C6D019B4DB66"},{"vulnerable":true,"criteria":"cpe:2.3:a:funk_software:funk_software_proxy:3.06:*:*:*:*:*:*:*","matchCriteriaId":"C4F701BB-4525-42A7-80AF-51D127A836B5"},{"vulnerable":true,"criteria":"cpe:2.3:a:funk_software:funk_software_proxy:3.09:*:*:*:*:*:*:*","matchCriteriaId":"FC126FFF-687F-41AA-BC77-E577D05B4BB8"},{"vulnerable":true,"criteria":"cpe:2.3:a:funk_software:funk_software_proxy:3.09a:*:*:*:*:*:*:*","matchCriteriaId":"A2A9E9AA-CC99-41E5-95C7-6DCAA0B0F6A0"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2002","CveId":"65","Ordinal":"1","Title":"CVE-2002-0065","CVE":"CVE-2002-0065","Year":"2002"},"notes":[{"CveYear":"2002","CveId":"65","Ordinal":"1","NoteData":"Funk Software Proxy Host 3.x uses weak encryption for the Proxy Host password, which allows local users to gain privileges by recovering the passwords from the PHOST.INI file or the Windows registry.","Type":"Description","Title":"CVE-2002-0065"},{"CveYear":"2002","CveId":"65","Ordinal":"2","NoteData":"2002-06-25","Type":"Other","Title":"Published"},{"CveYear":"2002","CveId":"65","Ordinal":"3","NoteData":"2002-06-15","Type":"Other","Title":"Modified"}]}}}