First published: Thu Sep 16 1999(Updated: )
WWWBoard stores encrypted passwords in a password file that is under the web root and thus accessible by remote attackers.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Wwwboard | =2.0_alpha_2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-1999-0953 has a high severity due to the exposure of encrypted passwords in a publicly accessible password file.
To fix CVE-1999-0953, move the password file outside the web root directory to protect it from remote access.
CVE-1999-0953 specifically affects WWWBoard version 2.0_alpha_2.1.
The impact of CVE-1999-0953 allows remote attackers to access encrypted passwords, potentially leading to unauthorized access.
While CVE-1999-0953 is an older vulnerability, it highlights ongoing risks related to insecure password storage practices in web applications.