CVE-2004-2524
clogin.php in Benchmark Designs' WHM AutoPilot 2.4.5 and earlier allows remote attackers to obtain plaintext username and password credentials by using the clogin_e and base64_encode functions to encode the desired user ID in the c parameter, then read…
Does this matter?
Lower severity and a low EPSS score (1.72%). Track it; it rarely justifies an emergency change on its own.
Description
clogin.php in Benchmark Designs' WHM AutoPilot 2.4.5 and earlier allows remote attackers to obtain plaintext username and password credentials by using the clogin_e and base64_encode functions to encode the desired user ID in the c parameter, then read the plaintext values in the resulting form.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 1.72% probability · 76th percentile
- CISA KEV
- Not listed
- Affected
- whm autopilot/whm autopilot
- Source
- cve@mitre.org
References
- http://archives.neohapsis.com/archives/fulldisclosure/2004-07/1310.htmlVendor Advisory
- http://secunia.com/advisories/12200Patch, Vendor Advisory
- http://securitytracker.com/id?1010833Exploit, Vendor Advisory
- http://www.osvdb.org/8279
- http://www.securityfocus.com/bid/10846
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16849
- http://archives.neohapsis.com/archives/fulldisclosure/2004-07/1310.htmlVendor Advisory
- http://secunia.com/advisories/12200Patch, Vendor Advisory
- http://securitytracker.com/id?1010833Exploit, Vendor Advisory
- http://www.osvdb.org/8279
- http://www.securityfocus.com/bid/10846
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16849
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.