Vulnerability Description
SHOUTcast 1.8.9 and earlier allows local users to obtain the cleartext administrative password via a GET request to port 8001, which causes the password to be logged in the world-readable sc_serv.log file.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Nullsoft | Shoutcast Server | 1.8.9 |
References
- http://archives.neohapsis.com/archives/bugtraq/2002-08/0017.htmlExploitPatchVendor Advisory
- http://www.iss.net/security_center/static/9775.phpVendor Advisory
- http://www.securityfocus.com/bid/5414PatchVendor Advisory
- http://archives.neohapsis.com/archives/bugtraq/2002-08/0017.htmlExploitPatchVendor Advisory
- http://www.iss.net/security_center/static/9775.phpVendor Advisory
- http://www.securityfocus.com/bid/5414PatchVendor Advisory
FAQ
What is CVE-2002-1470?
CVE-2002-1470 is a vulnerability with a CVSS score of 2.1 (LOW). SHOUTcast 1.8.9 and earlier allows local users to obtain the cleartext administrative password via a GET request to port 8001, which causes the password to be logged in the world-readable sc_serv.log ...
How severe is CVE-2002-1470?
CVE-2002-1470 has been rated LOW with a CVSS base score of 2.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2002-1470?
Check the references section above for vendor advisories and patch information. Affected products include: Nullsoft Shoutcast Server.