CVE-2002-1470: Low severity NullSoft Shoutcast Server vulnerability
SHOUTcast 1.8.9 and earlier allows local users to obtain the cleartext administrative password via a GET request to port 8001, which causes the password to be logged in the world-readable scserv.log file.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2002-1470?
CVE-2002-1470 is considered a high severity vulnerability due to the potential exposure of sensitive administrative credentials.
How do I fix CVE-2002-1470?
To fix CVE-2002-1470, upgrade to a later version of the SHOUTcast server that addresses this logging vulnerability.
Who is affected by CVE-2002-1470?
Local users with access to the system running SHOUTcast server version 1.8.9 or earlier may exploit CVE-2002-1470.
What version of SHOUTcast server is impacted by CVE-2002-1470?
CVE-2002-1470 impacts SHOUTcast server version 1.8.9 and earlier.
What are the consequences of CVE-2002-1470 exploitation?
Exploitation of CVE-2002-1470 allows unauthorized users to retrieve the cleartext administrative password, compromising server security.