Vulnerability Description
The GetPassword function in function.php of SiteNews 0.10 and 0.11 allows remote attackers to gain privileges and add users by providing a non-existent user name and the MD5 checksum for an empty password to add_user.php, which causes GetPassword to produce and compare a blank password for the non-existent user.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sitenews | Sitenews | 0.01_beta |
References
- http://marc.info/?l=bugtraq&m=101388393808699&w=2
- http://www.securityfocus.com/bid/4046
- https://exchange.xforce.ibmcloud.com/vulnerabilities/8181
- http://marc.info/?l=bugtraq&m=101388393808699&w=2
- http://www.securityfocus.com/bid/4046
- https://exchange.xforce.ibmcloud.com/vulnerabilities/8181
FAQ
What is CVE-2002-0286?
CVE-2002-0286 is a vulnerability with a CVSS score of 7.5 (HIGH). The GetPassword function in function.php of SiteNews 0.10 and 0.11 allows remote attackers to gain privileges and add users by providing a non-existent user name and the MD5 checksum for an empty pass...
How severe is CVE-2002-0286?
CVE-2002-0286 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2002-0286?
Check the references section above for vendor advisories and patch information. Affected products include: Sitenews Sitenews.