CVE-2002-1656

X-News <1.1 - Auth Bypass

Title source: llm
STIX 2.1

Description

X-News (x_news) 1.1 and earlier allows attackers to authenticate as other users by obtaining the MD5 checksum of the password, e.g. via sniffing or the users.txt data file, and providing it in a cookie.

Exploits (1)

exploitdb WRITEUP VERIFIED
by bd0rk · textwebappsphp
https://www.exploit-db.com/exploits/3043

References (5)

Core 5
Core References
US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/162723
Exploit vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1003828
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/8465
Various Sources x_refsource_misc
http://www.ifrance.com/kitetoua/tuto/x_holes.txt
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/4283

Scores

EPSS 0.1421
EPSS Percentile 94.4%

Details

Status published
Products (2)
xqus/x-news 1.0
xqus/x-news 1.1
Published Dec 31, 2002
Tracked Since Feb 18, 2026