Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2002-0324

Опубликовано: 25 июн. 2002
Источник: nvd
CVSS2: 7.5
EPSS Низкий

Описание

Greymatter 1.21c and earlier with the Bookmarklet feature enabled allows remote attackers to read a cleartext password and gain administrative privileges by guessing the name of a gmrightclick-*.reg file which contains the administrator name and password in cleartext, then retrieving the file from the web server before the Greymatter administrator performs a "Clear And Exit" action.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:noah_gray:graymatter:1.1:*:*:*:*:*:*:*
cpe:2.3:a:noah_gray:graymatter:1.1b:*:*:*:*:*:*:*
cpe:2.3:a:noah_gray:graymatter:1.2b:*:*:*:*:*:*:*
cpe:2.3:a:noah_gray:graymatter:1.21:*:*:*:*:*:*:*

EPSS

Процентиль: 76%
0.00943
Низкий

7.5 High

CVSS2

Дефекты

NVD-CWE-Other

Связанные уязвимости

github
почти 4 года назад

Greymatter 1.21c and earlier with the Bookmarklet feature enabled allows remote attackers to read a cleartext password and gain administrative privileges by guessing the name of a gmrightclick-*.reg file which contains the administrator name and password in cleartext, then retrieving the file from the web server before the Greymatter administrator performs a "Clear And Exit" action.

EPSS

Процентиль: 76%
0.00943
Низкий

7.5 High

CVSS2

Дефекты

NVD-CWE-Other