CVE-2001-1354

N

etWin Authentication module (NWAuth) 2.0 and 3.0b, as implemented in SurgeFTP, DMail, and possibly other packages, uses weak password hashing, which could allow local users to decrypt passwords or use a different password that has the same hash value as the correct password.

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:netwin:dmail:2.5d:*:*:*:*:*:*:*
cpe:2.3:a:netwin:dmail:2.7:*:*:*:*:*:*:*
cpe:2.3:a:netwin:dmail:2.7q:*:*:*:*:*:*:*
cpe:2.3:a:netwin:dmail:2.7r:*:*:*:*:*:*:*
cpe:2.3:a:netwin:dmail:2.8e:*:*:*:*:*:*:*
cpe:2.3:a:netwin:dmail:2.8f:*:*:*:*:*:*:*
cpe:2.3:a:netwin:dmail:2.8g:*:*:*:*:*:*:*
cpe:2.3:a:netwin:dmail:2.8h:*:*:*:*:*:*:*
cpe:2.3:a:netwin:dmail:2.8i:*:*:*:*:*:*:*
cpe:2.3:a:netwin:surgeftp:1.0b:*:*:*:*:*:*:*
cpe:2.3:a:netwin:surgeftp:2.0a:*:*:*:*:*:*:*
cpe:2.3:a:netwin:surgeftp:2.0b:*:*:*:*:*:*:*

History

20 Nov 2024, 23:37

Type Values Removed Values Added
References () http://online.securityfocus.com/archive/1/198293 - Vendor Advisory () http://online.securityfocus.com/archive/1/198293 - Vendor Advisory
References () http://www.securityfocus.com/bid/3075 - Exploit, Vendor Advisory () http://www.securityfocus.com/bid/3075 - Exploit, Vendor Advisory
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/6866 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/6866 -

Information

Published : 2001-07-20 04:00

Updated : 2025-04-03 01:03


NVD link : CVE-2001-1354

Mitre link : CVE-2001-1354

CVE.ORG link : CVE-2001-1354


JSON object : View

Products Affected