Record summary

CVE-2001-1354 has a selected CVSS score of 4.6; EIP currently links 1 catalogued exploit.

Description

NetWin Authentication module (NWAuth) 2.0 and 3.0b, as implemented in SurgeFTP, DMail, and possibly other packages, uses weak password hashing, which could allow local users to decrypt passwords or use a different password that has the same hash value as the correct password.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBNetWin DMail 2.x / SurgeFTP 1.0/2.0 - Weak Password EncryptionExploitDB exploitby byterageNot analyzed1 file
ExploitDB

PoC details

References

4