X-News Insecure User Database...

- AV AC AU C I A
发布: 2002-03-13
修订: 2025-04-13

X-News is a news management system, written in PHP. X-News uses a flat-file database to store information. It will run on most Unix and Linux variants, as well as Microsoft Windows operating systems. X-News stores user IDs and MD5 hashes in a world-readable file (db/users.txt). This is the same information that is issued by X-News in cookie-based authentication credentials. An attacker may incorporate this information into cookies and then submit them to gain unauthorized access to the X-News administrative account.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息