phpRank 1.8 stores the administrative password in plaintext on the server and in the "ap" cookie, which allows remote attackers to retrieve the administrative password.
The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/5947 | broken link third party advisory vdb entry |
http://www.iss.net/security_center/static/10352.php | vdb entry broken link |
http://archives.neohapsis.com/archives/bugtraq/2002-10/0148.html | vendor advisory broken link mailing list |