The default "basic" security setting' in config.php for TWIG webmail 2.7.4 and earlier stores cleartext usernames and passwords in cookies, which could allow attackers to obtain authentication information and gain privileges.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2005-07-14T04:00:00
Updated: 2024-08-08T04:58:11.429Z
Reserved: 2005-07-14T00:00:00
Link: CVE-2001-1537
Vulnrichment
No data.
NVD
Status : Modified
Published: 2001-12-31T05:00:00.000
Modified: 2024-11-20T23:37:55.373
Link: CVE-2001-1537
Redhat
No data.