CVE-2001-1537
N/A
N/A
Summary
The default "basic" security setting' in config.php for TWIG webmail 2.7.4 and earlier stores cleartext usernames and passwords in cookies, which could allow attackers to obtain authentication information and gain privileges.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| n/a | n/a | n/a | affected |
Weaknesses
- n/a
ADP Enrichment
CVE Program Container
Additional References
- http://archives.neohapsis.com/archives/bugtraq/2001-11/0245.html
- http://www.securityfocus.com/bid/3591
- http://www.iss.net/security_center/static/7619.php
References
- http://archives.neohapsis.com/archives/bugtraq/2001-11/0245.html
- http://www.securityfocus.com/bid/3591
- http://www.iss.net/security_center/static/7619.php
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.