20011025 Weak authentication in iBill's Password Management CGImailing list
http://marc.info/?l=bugtraq&m=100404371423927&w=2 CVE-2001-0839
iBill Management Script - Weak Hard-Coded Password
Record summary
CVE-2001-0839 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.
Description
ibillpm.pl in iBill password management system generates weak passwords based on a client's MASTER_ACCOUNT, which allows remote attackers to modify account information in the .htpasswd file via brute force password guessing.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBiBill Management Script - Weak Hard-Coded PasswordExploitDB exploitby MK UltraNot analyzed1 file
References
43476vdb entry
http://www.securityfocus.com/bid/3476 ibillpm-cgi-insecure-password(7352)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/7352 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2001-0839