CVE-2004-2524
Last modified
CVE-2004-2524 is a vulnerability of currently unknown severity. clogin.php in Benchmark Designs' WHM AutoPilot 2.4.5 and earlier allows remote attackers to obtain plaintext username and password credentials by using the clogin_e and base64_encode functions to encode the desired user ID in the c parameter, then read the plaintext values in the resulting form.. EPSS estimates a 1.72% chance of exploitation in the next 30 days.
Description
clogin.php in Benchmark Designs' WHM AutoPilot 2.4.5 and earlier allows remote attackers to obtain plaintext username and password credentials by using the clogin_e and base64_encode functions to encode the desired user ID in the c parameter, then read the plaintext values in the resulting form.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Whm Autopilot | Whm Autopilot | 2.4.5 |
References
- http://secunia.com/advisories/12200Patch, Vendor Advisory
- http://securitytracker.com/id?1010833Exploit, Vendor Advisory
- http://secunia.com/advisories/12200Patch, Vendor Advisory
- http://securitytracker.com/id?1010833Exploit, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2004-2524?
How severe is CVE-2004-2524?
How do I fix CVE-2004-2524?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2004
- CVE-2004-2518Gattaca Server 2003 1.1.10.0 allows remote attackers to obta…
- CVE-2004-2519Gattaca Server 2003 1.1.10.0 allows remote attackers to caus…
- CVE-2004-2520POP3 protocol in Gattaca Server 2003 1.1.10.0 allows remote …
- CVE-2004-2521Mail server in Gattaca Server 2003 1.1.10.0 allows remote at…
- CVE-2004-2522Cross-site scripting (XSS) vulnerability in web.tmpl in Gatt…
- CVE-2004-2523Format string vulnerability in the msg command (cat_message …
- CVE-2004-2525Cross-site scripting (XSS) vulnerability in compat.php in Se…
- CVE-2004-2526Directory traversal vulnerability in ldacgi.exe in IBM Tivol…
- CVE-2004-2527The local and remote desktop login screens in Microsoft Wind…
- CVE-2004-2528Cross-site scripting (XSS) vulnerability in sresult.exe in W…
- CVE-2004-2529Gadu-Gadu allows remote attackers to bypass the "image send"…
- CVE-2004-2530Visual truncation vulnerability in Gadu-Gadu allows remote a…
Are you affected by CVE-2004-2524?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
