aRCHILLES Newsworld

CPE Details

aRCHILLES Newsworld
-
2024-03-07
12h19 +00:00
2024-03-07
12h19 +00:00
Alerte pour un CPE
Restez informé de toutes modifications pour un CPE spécifique.
Gestion des notifications

CPE Name: cpe:2.3:a:archilles:newsworld:-:*:*:*:*:*:*:*

Informations

Vendor

archilles

Product

newsworld

Version

-

Related CVE

Open and find in CVE List

CVE ID Publié Description Score Gravité
CVE-2005-3434 2005-11-02 10h00 +00:00 Archilles Newsworld before 1.5.0-rc1 stores (1) account.nwd and (2) session.nwd under the web root with insufficient access control, which allows remote attackers to obtain sensitive information such as usernames, hashed passwords, and session IDs, and gain privileges.
7.5
CVE-2005-3435 2005-11-02 10h00 +00:00 admin_news.php in Archilles Newsworld up to 1.3.0 allows attackers to bypass authentication by obtaining the password hash for another user, for example through another Newsworld vulnerability, and specifying the hash in the pwd argument.
9.8
Critique