VulnerabilityModified
CVE-2002-1353
LocalWEB2000 HTTP server 2.1.0 stores passwords in plain text under the web document root in users.lst, which allows remote attackers to obtain the passwords via a direct request to users.lst.
MEDIUM 5.0EPSS 1.39%
Does this matter?
Lower severity and a low EPSS score (1.39%). Track it; it rarely justifies an emergency change on its own.
Description
LocalWEB2000 HTTP server 2.1.0 stores passwords in plain text under the web document root in users.lst, which allows remote attackers to obtain the passwords via a direct request to users.lst.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 1.39% probability · 71th percentile
- CISA KEV
- Not listed
- Affected
- intranet-server/localweb2000
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/7740/
- http://securitytracker.com/id?1005830
- http://www.idefense.com/application/poi/display?id=31&type=vulnerabilities&flashstatus=false
- https://exchange.xforce.ibmcloud.com/vulnerabilities/10948
- http://secunia.com/advisories/7740/
- http://securitytracker.com/id?1005830
- http://www.idefense.com/application/poi/display?id=31&type=vulnerabilities&flashstatus=false
- https://exchange.xforce.ibmcloud.com/vulnerabilities/10948
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.