CVE-2004-2524
Last modified
CVE-2004-2524 is a vulnerability of currently unknown severity. clogin.php in Benchmark Designs' WHM AutoPilot 2.4.5 and earlier allows remote attackers to obtain plaintext username and password credentials by using the clogin_e and base64_encode functions to encode the desired user ID in the c parameter, then read the plaintext values in the resulting form.. EPSS estimates a 1.72% chance of exploitation in the next 30 days.
Description
clogin.php in Benchmark Designs' WHM AutoPilot 2.4.5 and earlier allows remote attackers to obtain plaintext username and password credentials by using the clogin_e and base64_encode functions to encode the desired user ID in the c parameter, then read the plaintext values in the resulting form.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Whm Autopilot | Whm Autopilot | 2.4.5 |
References
- http://secunia.com/advisories/12200Patch, Vendor Advisory
- http://securitytracker.com/id?1010833Exploit, Vendor Advisory
- http://secunia.com/advisories/12200Patch, Vendor Advisory
- http://securitytracker.com/id?1010833Exploit, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2004-2524?
How severe is CVE-2004-2524?
How do I fix CVE-2004-2524?
Are you affected by CVE-2004-2524?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
