Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

NetWin WebNEWS Default Account Vulnerability

WebNEWS is a server product designed to provide access to news groups through a web interface. It is able to connect to any standard NNTP server, and is available for Windows, BSD, Linux and most Unix systems.

WebNEWS contains a number of default accounts which have been hard-coded into the program.

The following default accounts exist (username/password):

testweb/newstest, alwn3845/imaptest, alwi3845/wtest3452, testweb2/wtest4879

A remote attacker who is aware of these default accounts may use them to gain unauthorized access to the WebNEWS service.







 

Privacy Statement
Copyright 2008, SecurityFocus