CVE-2002-1910
HIGHClick2Learn Ingenium Learning Management System 5.1 and 6.1 - Inadequate Encryption Strength
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2002-1910. PoCs published by Brian Enigma.
AI-analyzed exploit summary This Java program decodes weakly hashed passwords used by Ingenium Learning Management System by reversing a Caesar cipher with a rotating key. It requires access to the hashed password from the config.txt file, which may be obtained via another vulnerability (e.g., directory traversal).
Description
Click2Learn Ingenium Learning Management System 5.1 and 6.1 uses weak encryption for passwords (reversible algorithm), which allows attackers to obtain passwords.
Exploits (1)
This Java program decodes weakly hashed passwords used by Ingenium Learning Management System by reversing a Caesar cipher with a rotating key. It requires access to the hashed password from the config.txt file, which may be obtained via another vulnerability (e.g., directory traversal).
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N