PHP TopSites Plaintext User Password Weakness
BID:6623
Info
PHP TopSites Plaintext User Password Weakness
| Bugtraq ID: | 6623 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 15 2003 12:00AM |
| Updated: | Jan 15 2003 12:00AM |
| Credit: | The discovery of this vulnerability has been credited to the Cyberarmy Application and Code Auditing Team <[email protected]>. |
| Vulnerable: |
iTop10 PHP TopSites Pro 2.2 iTop10 PHP TopSites Free 2.0 B |
| Not Vulnerable: | |
Discussion
PHP TopSites Plaintext User Password Weakness
A weakness has been discovered in PHP TopSites. It has been reported that user's passwords are stored in plaintext and thus are visible to TopSites administrators. This poses a security risk as TopSite script users may use the same passwords on other systems.
A weakness has been discovered in PHP TopSites. It has been reported that user's passwords are stored in plaintext and thus are visible to TopSites administrators. This poses a security risk as TopSite script users may use the same passwords on other systems.
Exploit / POC
PHP TopSites Plaintext User Password Weakness
No exploit is required.
No exploit is required.
Solution / Fix
PHP TopSites Plaintext User Password Weakness
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
PHP TopSites Plaintext User Password Weakness
References:
References:
- Multiple PHP Topsites Vulnerabities found (Cyberarmy Application and Code Auditing Team
)