{"api_version":"1","generated_at":"2026-07-23T05:16:12+00:00","cve":"CVE-2002-2143","urls":{"html":"https://cve.report/CVE-2002-2143","api":"https://cve.report/api/cve/CVE-2002-2143.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2002-2143","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2002-2143"},"summary":{"title":"CVE-2002-2143","description":"The admin.html file in MySimple News 1.0 stores its administrative password in plaintext, which allows remote attackers to gain unauthorized access to the web server by viewing the source of admin.html.","state":"PUBLISHED","assigner":"mitre","published_at":"2002-12-31 05:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://www.securityfocus.com/archive/1/293871","name":"http://www.securityfocus.com/archive/1/293871","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/5866","name":"http://www.securityfocus.com/bid/5866","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"MySimpleNews Remotely Readable Administrator Password Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.iss.net/security_center/static/10298.php","name":"http://www.iss.net/security_center/static/10298.php","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"ISS X-Force Database: mysimplenews-admin-plaintext-password (10298): MySimpleNews admin.html file stores administrative password in plain text","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2002-2143","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2002-2143","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2002","cve_id":"2143","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mysimplenews","cpe5":"mysimplenews","cpe6":"1.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-08T03:51:17.536Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"5866","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/5866"},{"name":"mysimplenews-admin-plaintext-password(10298)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"http://www.iss.net/security_center/static/10298.php"},{"name":"20021002 MySimpleNews (PHP)","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/293871"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2002-10-02T00:00:00.000Z","descriptions":[{"lang":"en","value":"The admin.html file in MySimple News 1.0 stores its administrative password in plaintext, which allows remote attackers to gain unauthorized access to the web server by viewing the source of admin.html."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2016-11-17T15:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"5866","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/5866"},{"name":"mysimplenews-admin-plaintext-password(10298)","tags":["vdb-entry","x_refsource_XF"],"url":"http://www.iss.net/security_center/static/10298.php"},{"name":"20021002 MySimpleNews (PHP)","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/293871"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2002-2143","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The admin.html file in MySimple News 1.0 stores its administrative password in plaintext, which allows remote attackers to gain unauthorized access to the web server by viewing the source of admin.html."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"5866","refsource":"BID","url":"http://www.securityfocus.com/bid/5866"},{"name":"mysimplenews-admin-plaintext-password(10298)","refsource":"XF","url":"http://www.iss.net/security_center/static/10298.php"},{"name":"20021002 MySimpleNews (PHP)","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/293871"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2002-2143","datePublished":"2005-11-16T21:17:00.000Z","dateReserved":"2005-11-16T00:00:00.000Z","dateUpdated":"2024-08-08T03:51:17.536Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2002-12-31 05:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":true,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:mysimplenews:mysimplenews:1.0:*:*:*:*:*:*:*","matchCriteriaId":"710BB288-144A-4D13-8239-B253298E292A"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2002","CveId":"2143","Ordinal":"1","Title":"CVE-2002-2143","CVE":"CVE-2002-2143","Year":"2002"},"notes":[{"CveYear":"2002","CveId":"2143","Ordinal":"1","NoteData":"The admin.html file in MySimple News 1.0 stores its administrative password in plaintext, which allows remote attackers to gain unauthorized access to the web server by viewing the source of admin.html.","Type":"Description","Title":"CVE-2002-2143"},{"CveYear":"2002","CveId":"2143","Ordinal":"2","NoteData":"2005-11-16","Type":"Other","Title":"Published"},{"CveYear":"2002","CveId":"2143","Ordinal":"3","NoteData":"2016-11-17","Type":"Other","Title":"Modified"}]}}}