20010720 NetWin Authentication Module 3.0b password storage vulnerabilities / buffer overflowsmailing list
http://online.securityfocus.com/archive/1/198293 CVE-2001-1354
NetWin DMail 2.x / SurgeFTP 1.0/2.0 - Weak Password Encryption
Record summary
CVE-2001-1354 has a selected CVSS score of 4.6; EIP currently links 1 catalogued exploit.
Description
NetWin Authentication module (NWAuth) 2.0 and 3.0b, as implemented in SurgeFTP, DMail, and possibly other packages, uses weak password hashing, which could allow local users to decrypt passwords or use a different password that has the same hash value as the correct password.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBNetWin DMail 2.x / SurgeFTP 1.0/2.0 - Weak Password EncryptionExploitDB exploitby byterageNot analyzed1 file
References
43075vdb entry
http://www.securityfocus.com/bid/3075 netwin-nwauth-weak-encryption(6866)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/6866 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2001-1354