X-News (x_news) 1.1 and earlier allows attackers to authenticate as other users by obtaining the MD5 checksum of the password, e.g. via sniffing or the users.txt data file, and providing it in a cookie.
Link | Tags |
---|---|
http://www.kb.cert.org/vuls/id/162723 | third party advisory us government resource |
http://securitytracker.com/id?1003828 | vdb entry exploit |
https://exchange.xforce.ibmcloud.com/vulnerabilities/8465 | vdb entry |
http://www.ifrance.com/kitetoua/tuto/x_holes.txt | |
http://www.securityfocus.com/bid/4283 | vdb entry |