Bugtraq mailing list archives

Netwin Webnews 1.1k


From: Shai <shai () akn-systems com>
Date: Thu, 21 Feb 2002 18:19:01 +0200

Name: Netwin WebNews 1.1k
Operation system: tested under Redhat linux 7.0
Vendor status: The vendor has been contacted on the 20th of February and
hasn't replied yet.
Description:
The Netwin Webnews version 1.1k CGI (binaries) contains 4 default users
(within the binary) that can not be removed.

While running the "strings" command over the file webnews.pl, the users are
revealed:

testweb
newstest
alwn3845
imaptest
alwi3845
wtest3452
testweb2
wtest4879

For instance, testweb is the username and newstest is it's password.

Best regards,
Shai
Chief Hacking Officer
AKN Systems



Current thread: