admin.php in Newsletter ZWS allows remote attackers to gain administrative privileges via a list_user operation with the ulevel parameter set to 1 (administrator level), which lists all users and their passwords.
References
Configurations
History
No history.
Information
Published : 2004-12-06 05:00
Updated : 2025-04-03 01:03
NVD link : CVE-2004-0621
Mitre link : CVE-2004-0621
CVE.ORG link : CVE-2004-0621
JSON object : View
Products Affected
zaireweb_solutions
- newsletter_zws
CWE