CVE-2002-0310

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
31/05/2002
Last modified:
03/04/2025

Description

Netwin WebNews 1.1k CGI program includes several default usernames and cleartext passwords that cannot be deleted by the administrator, which allows remote attackers to gain privileges via the username/password combinations (1) testweb/newstest, (2) alwn3845/imaptest, (3) alwi3845/wtest3452, or (4) testweb2/wtest4879.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:netwin:webnews:1.1h:*:*:*:*:*:*:*
cpe:2.3:a:netwin:webnews:1.1i:*:*:*:*:*:*:*
cpe:2.3:a:netwin:webnews:1.1j:*:*:*:*:*:*:*
cpe:2.3:a:netwin:webnews:1.1k:*:*:*:*:*:*:*