CVE-2003-1454: Medium severity Linux Linux kernel vulnerability
Published Dec 31, 2003
·Updated
Invision Power Services Invision Board 1.0 through 1.1.1, when a forum is password protected, stores the administrator password in a cookie in plaintext, which could allow remote attackers to gain access.
Affected Software
12 affected components
Linux Linux kernel
Microsoft All Windows
Unix Unix
Invision Power Services Invision Board=1.0
Invision Power Services Invision Board=1.0.1
Invision Power Services Invision Board=1.1.1
All of the following
Any of the following
Linux Linux kernel
Microsoft All Windows
Unix Unix
Any of the following
Invision Power Services Invision Board=1.0
Invision Power Services Invision Board=1.0.1
Invision Power Services Invision Board=1.1.1
Event History
Dec 31, 2003
CVE Published
05:00 AM
Data Sourced
05:00 AM
DescriptionWeaknessAffected Software
Data Sourced
via NVD·05:00 AM
DescriptionSeverityAffected Software
Oct 23, 2007
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2003-1454?
CVE-2003-1454 is classified as a medium severity vulnerability due to the exposure of administrator passwords in plaintext.
2
How do I fix CVE-2003-1454?
To fix CVE-2003-1454, upgrade to a newer version of Invision Board that does not store passwords in plaintext.
3
Which versions of Invision Board are affected by CVE-2003-1454?
CVE-2003-1454 affects Invision Board version 1.0 through 1.1.1.
4
What are the risks associated with CVE-2003-1454?
The main risk associated with CVE-2003-1454 is unauthorized access to the forum due to leaked administrator passwords.
5
Can CVE-2003-1454 be exploited remotely?
Yes, CVE-2003-1454 can be exploited remotely by attackers who can access the stored cookies.