Netwin WebNews 1.1k CGI program includes several default usernames and cleartext passwords that cannot be deleted by the administrator, which allows remote attackers to gain privileges via the username/password combinations (1) testweb/newstest, (2) alwn3845/imaptest, (3) alwi3845/wtest3452, or (4) testweb2/wtest4879.
Link | Tags |
---|---|
http://marc.info/?l=bugtraq&m=101432236729631&w=2 | mailing list |
http://www.securityfocus.com/bid/4156 | vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/8255 | vdb entry |