MiniHTTPServer WebForums Server Default Password Vulnerability
BID:8620
Info
MiniHTTPServer WebForums Server Default Password Vulnerability
| Bugtraq ID: | 8620 |
| Class: | Configuration Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 15 2003 12:00AM |
| Updated: | Sep 15 2003 12:00AM |
| Credit: | The discovery of this issue has been credited to Peter Winter-Smith. |
| Vulnerable: |
Minihttp WebForum Server 1.5 |
| Not Vulnerable: | |
Discussion
MiniHTTPServer WebForums Server Default Password Vulnerability
It has been reported that WebForums Server is prone to a default password issue that may allow a remote attacker to login to an 'admin' account by using the '"' character as a password.
This issue may allow an attacker to gain administrative access on a default installation of the software and may allow access to the 'C:\' drive.
It has been reported that WebForums Server is prone to a default password issue that may allow a remote attacker to login to an 'admin' account by using the '"' character as a password.
This issue may allow an attacker to gain administrative access on a default installation of the software and may allow access to the 'C:\' drive.
References
MiniHTTPServer WebForums Server Default Password Vulnerability
References:
References:
- Forum Web Server Product Page (Mini HTTP Server)