
Find real vulnerabilities before they ship
Excite for Web Servers (EWS) 1.1 allows local users to gain privileges by obtaining the encrypted password from the world-readable Architext.conf authentication file and replaying the encrypted password in an HTTP request to AT-generated.cgi or AT-admin.cgi.
| Base Score | 7.2 |
|---|---|
| Vector String | AV:L/AC:L/Au:N/C:C/I:C/A:C |
| Base Severity | Unknown |
| Version | 2.0 |
| Attack Vector (AV) |