Vulnerabilities > CVE-2002-1353 - Remote Security vulnerability in Intranet-Server Localweb2000 2.1.0

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
network
low complexity
intranet-server

Summary

LocalWEB2000 HTTP server 2.1.0 stores passwords in plain text under the web document root in users.lst, which allows remote attackers to obtain the passwords via a direct request to users.lst.

Vulnerable Configurations

Part Description Count
Application
Intranet-Server
1