EasyNews is a free, open-source script for displaying news stories on a website. The administrative password is stored in plaintext in the file 'settings.php'. A local attacker may obtain the administrative password by viewing 'settings.php'. This may also be exploitable through other vulnerabilities in web applications that allow for disclosure of file contents.
EasyNews is a free, open-source script for displaying news stories on a website. The administrative password is stored in plaintext in the file 'settings.php'. A local attacker may obtain the administrative password by viewing 'settings.php'. This may also be exploitable through other vulnerabilities in web applications that allow for disclosure of file contents.