PHPRank Administrator Password Plain Text Storage Vulnerability
BID:5947
Info
PHPRank Administrator Password Plain Text Storage Vulnerability
| Bugtraq ID: | 5947 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Oct 10 2002 12:00AM |
| Updated: | Oct 10 2002 12:00AM |
| Credit: | Vulnerability discovery credited to Jedi/Sector One <[email protected]>. |
| Vulnerable: |
phpRank phpRank 1.8 |
| Not Vulnerable: | |
Discussion
PHPRank Administrator Password Plain Text Storage Vulnerability
phpRank is a freely available web site link sharing script. It is available for Unix, Linux, and Microsoft operating systems.
It has been reported that phpRank does not safely store the administrator password in some circumstances. phpRank stores the administrative password in plain text on the server side when the password has been set. Additionally, once the administrator has accessed the web administration interface, and enabled the cookie storage of authentication credentials, the password is stored in plain text in the authentication cookie.
phpRank is a freely available web site link sharing script. It is available for Unix, Linux, and Microsoft operating systems.
It has been reported that phpRank does not safely store the administrator password in some circumstances. phpRank stores the administrative password in plain text on the server side when the password has been set. Additionally, once the administrator has accessed the web administration interface, and enabled the cookie storage of authentication credentials, the password is stored in plain text in the authentication cookie.
Exploit / POC
PHPRank Administrator Password Plain Text Storage Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
PHPRank Administrator Password Plain Text Storage Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
PHPRank Administrator Password Plain Text Storage Vulnerability
References:
References:
- phpRank Homepage (phpRank)