Lucene search

K
cve[email protected]CVE-2002-0537
HistoryJul 03, 2002 - 4:00 a.m.

CVE-2002-0537

2002-07-0304:00:00
web.nvd.nist.gov
23
sws 2.5
remote attack
admin.html
cve-2002-0537
gain administrative privileges

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

7.3 High

AI Score

Confidence

Low

0.006 Low

EPSS

Percentile

79.5%

The admin.html file in StepWeb Search Engine (SWS) 2.5 stores passwords in links to manager.pl, which allows remote attackers who can access the admin.html file to gain administrative privileges to SWS.

Affected configurations

NVD
Node
stepwebswsMatch2.5
CPENameOperatorVersion
stepweb:swsstepweb swseq2.5

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

7.3 High

AI Score

Confidence

Low

0.006 Low

EPSS

Percentile

79.5%

Related for CVE-2002-0537