MySimpleNews Remotely Readable Administrator Password Vulnerability
BID:5866
Info
MySimpleNews Remotely Readable Administrator Password Vulnerability
| Bugtraq ID: | 5866 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 02 2002 12:00AM |
| Updated: | Oct 02 2002 12:00AM |
| Credit: | Discovery credited to Frog Man <[email protected]>. |
| Vulnerable: |
MySimpleNews MySimpleNews 1.0 |
| Not Vulnerable: | |
Discussion
MySimpleNews Remotely Readable Administrator Password Vulnerability
MySimpleNews stores the administrative password in clear text in a remotely viewable HTML file.
Any remote user can view the contents of the HTML file to determine the administrator password.
MySimpleNews stores the administrative password in clear text in a remotely viewable HTML file.
Any remote user can view the contents of the HTML file to determine the administrator password.
Exploit / POC
MySimpleNews Remotely Readable Administrator Password Vulnerability
The administrator password can be found in the HTML code for admin.html below:
moncode = prompt('MySimpleNews - Administration','');
if (moncode != "[ADMINPASSWORD]")
{
location.href="about:Erreur 403";
}
The administrator password can be found in the HTML code for admin.html below:
moncode = prompt('MySimpleNews - Administration','');
if (moncode != "[ADMINPASSWORD]")
{
location.href="about:Erreur 403";
}
References
MySimpleNews Remotely Readable Administrator Password Vulnerability
References:
References: