NetWin WebNEWS Default Account Vulnerability
BID:4156
Info
NetWin WebNEWS Default Account Vulnerability
| Bugtraq ID: | 4156 |
| Class: | Design Error |
| CVE: |
CVE-2002-0310 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 21 2002 12:00AM |
| Updated: | Jul 11 2009 10:56AM |
| Credit: | This vulnerability was submitted to BugTraq on February 21st, 2002 by Shai <[email protected]>. |
| Vulnerable: |
NetWin WebNEWS 1.1 k NetWin WebNEWS 1.1 j NetWin WebNEWS 1.1 i NetWin WebNEWS 1.1 h |
| Not Vulnerable: | |
Discussion
NetWin WebNEWS Default Account Vulnerability
WebNEWS is a server product designed to provide access to news groups through a web interface. It is able to connect to any standard NNTP server, and is available for Windows, BSD, Linux and most Unix systems.
WebNEWS contains a number of default accounts which have been hard-coded into the program.
The following default accounts exist (username/password):
testweb/newstest, alwn3845/imaptest, alwi3845/wtest3452, testweb2/wtest4879
A remote attacker who is aware of these default accounts may use them to gain unauthorized access to the WebNEWS service.
WebNEWS is a server product designed to provide access to news groups through a web interface. It is able to connect to any standard NNTP server, and is available for Windows, BSD, Linux and most Unix systems.
WebNEWS contains a number of default accounts which have been hard-coded into the program.
The following default accounts exist (username/password):
testweb/newstest, alwn3845/imaptest, alwi3845/wtest3452, testweb2/wtest4879
A remote attacker who is aware of these default accounts may use them to gain unauthorized access to the WebNEWS service.
Exploit / POC
NetWin WebNEWS Default Account Vulnerability
There is no exploit required.
There is no exploit required.