The default "basic" security setting' in config.php for TWIG webmail 2.7.4 and earlier stores cleartext usernames and passwords in cookies, which could allow attackers to obtain authentication information and gain privileges.
Metrics
Affected Vendors & Products
References
History
No history.

Status: PUBLISHED
Assigner: mitre
Published: 2005-07-14T04:00:00
Updated: 2024-08-08T04:58:11.429Z
Reserved: 2005-07-14T00:00:00
Link: CVE-2001-1537

No data.

Status : Modified
Published: 2001-12-31T05:00:00.000
Modified: 2024-11-20T23:37:55.373
Link: CVE-2001-1537

No data.