Vulnerabilities > CVE-2001-0088 - Authentication Bypass vulnerability in Jason Hines PHPweblog 0.4.2
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
PARTIAL Integrity impact
PARTIAL Availability impact
PARTIAL Summary
common.inc.php in phpWebLog 0.4.2 does not properly initialize the $CONF array, which inadvertently sets the password to a single character, allowing remote attackers to easily guess the SiteKey and gain administrative privileges to phpWebLog.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |