Vulnerabilities > CVE-2007-2554 - Remote Security vulnerability in Newspower

047910
CVSS 7.8 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
COMPLETE
Availability impact
NONE
network
low complexity
associated-press

Summary

Associated Press (AP) Newspower 4.0.1 and earlier uses a default blank password for the MySQL root account, which allows remote attackers to insert or modify news articles via shows.tblscript.

Vulnerable Configurations

Part Description Count
Application
Associated_Press
1