{"api_version":"1","generated_at":"2026-07-23T10:11:12+00:00","cve":"CVE-2002-0537","urls":{"html":"https://cve.report/CVE-2002-0537","api":"https://cve.report/api/cve/CVE-2002-0537.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2002-0537","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2002-0537"},"summary":{"title":"CVE-2002-0537","description":"The admin.html file in StepWeb Search Engine (SWS) 2.5 stores passwords in links to manager.pl, which allows remote attackers who can access the admin.html file to gain administrative privileges to SWS.","state":"PUBLISHED","assigner":"mitre","published_at":"2002-07-03 04:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"10","severity":"","vector":"AV:N/AC:L/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","baseScore":10,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://www.iss.net/security_center/static/8849.php","name":"http://www.iss.net/security_center/static/8849.php","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"ISS X-Force Database: sws-insecure-admin-page (8849): StepWeb Search (SWS) insecure admin page","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://archives.neohapsis.com/archives/bugtraq/2002-04/0148.html","name":"http://archives.neohapsis.com/archives/bugtraq/2002-04/0148.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Patch","Vendor Advisory"],"title":"Neohapsis Archives - Bugtraq - SWS Vuln (small but important to those using it.) - From brainrawt@hotmail.com","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/4503","name":"http://www.securityfocus.com/bid/4503","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"StepWeb Search Engine Admin Webpage Access Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2002-0537","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2002-0537","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2002","cve_id":"537","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"stepweb","cpe5":"sws","cpe6":"2.5","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-08T02:49:28.915Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"sws-insecure-admin-page(8849)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"http://www.iss.net/security_center/static/8849.php"},{"name":"4503","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/4503"},{"name":"20020411 SWS Vuln (small but important to those using it.)","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://archives.neohapsis.com/archives/bugtraq/2002-04/0148.html"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2002-04-11T00:00:00.000Z","descriptions":[{"lang":"en","value":"The admin.html file in StepWeb Search Engine (SWS) 2.5 stores passwords in links to manager.pl, which allows remote attackers who can access the admin.html file to gain administrative privileges to SWS."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2002-06-15T09:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"sws-insecure-admin-page(8849)","tags":["vdb-entry","x_refsource_XF"],"url":"http://www.iss.net/security_center/static/8849.php"},{"name":"4503","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/4503"},{"name":"20020411 SWS Vuln (small but important to those using it.)","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://archives.neohapsis.com/archives/bugtraq/2002-04/0148.html"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2002-0537","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The admin.html file in StepWeb Search Engine (SWS) 2.5 stores passwords in links to manager.pl, which allows remote attackers who can access the admin.html file to gain administrative privileges to SWS."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"sws-insecure-admin-page(8849)","refsource":"XF","url":"http://www.iss.net/security_center/static/8849.php"},{"name":"4503","refsource":"BID","url":"http://www.securityfocus.com/bid/4503"},{"name":"20020411 SWS Vuln (small but important to those using it.)","refsource":"BUGTRAQ","url":"http://archives.neohapsis.com/archives/bugtraq/2002-04/0148.html"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2002-0537","datePublished":"2002-06-11T04:00:00.000Z","dateReserved":"2002-06-07T00:00:00.000Z","dateUpdated":"2024-08-08T02:49:28.915Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2002-07-03 04:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","baseScore":10,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":true,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:stepweb:sws:2.5:*:*:*:*:*:*:*","matchCriteriaId":"27B6F214-9F79-4BD4-8DE7-49F517ABAE39"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2002","CveId":"537","Ordinal":"1","Title":"CVE-2002-0537","CVE":"CVE-2002-0537","Year":"2002"},"notes":[{"CveYear":"2002","CveId":"537","Ordinal":"1","NoteData":"The admin.html file in StepWeb Search Engine (SWS) 2.5 stores passwords in links to manager.pl, which allows remote attackers who can access the admin.html file to gain administrative privileges to SWS.","Type":"Description","Title":"CVE-2002-0537"},{"CveYear":"2002","CveId":"537","Ordinal":"2","NoteData":"2002-06-11","Type":"Other","Title":"Published"},{"CveYear":"2002","CveId":"537","Ordinal":"3","NoteData":"2002-06-15","Type":"Other","Title":"Modified"}]}}}