The admin.html file in StepWeb Search Engine (SWS) 2.5 stores passwords in links to manager.pl, which allows remote attackers who can access the admin.html file to gain administrative privileges to SWS.
                
            References
                    | Link | Resource | 
|---|---|
| http://archives.neohapsis.com/archives/bugtraq/2002-04/0148.html | Exploit Patch Vendor Advisory | 
| http://www.iss.net/security_center/static/8849.php | Vendor Advisory | 
| http://www.securityfocus.com/bid/4503 | Patch Vendor Advisory | 
| http://archives.neohapsis.com/archives/bugtraq/2002-04/0148.html | Exploit Patch Vendor Advisory | 
| http://www.iss.net/security_center/static/8849.php | Vendor Advisory | 
| http://www.securityfocus.com/bid/4503 | Patch Vendor Advisory | 
Configurations
                    History
                    No history.
Information
                Published : 2002-07-03 04:00
Updated : 2025-04-03 01:03
NVD link : CVE-2002-0537
Mitre link : CVE-2002-0537
CVE.ORG link : CVE-2002-0537
JSON object : View
Products Affected
                stepweb
- sws
CWE
                