CVE-2002-1800

HIGH

phpRank 1.8 - Cleartext Storage of Sensitive Information in Administrative Password

Title source: llm
STIX 2.1

Description

phpRank 1.8 stores the administrative password in plaintext on the server and in the "ap" cookie, which allows remote attackers to retrieve the administrative password.

References (3)

Core 3
Core References
Broken Link, Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/5947
Broken Link vdb-entry x_refsource_xf
http://www.iss.net/security_center/static/10352.php
Broken Link, Vendor Advisory mailing-list x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2002-10/0148.html

Scores

CVSS v3 7.5
EPSS 0.0120
EPSS Percentile 64.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-312
Status published
Products (1)
phprank/phprank 1.8
Published Dec 31, 2002
Tracked Since Feb 18, 2026