CVE-1999-1073

CVSS 2.0 Score 7.2 of 10 (high)

Details

Published Nov 30, 1998
Updated: Nov 20, 2024

Summary

CVE-1999-1073 is a vulnerability affecting Excite for Web Servers (EWS) version 1.1. This issue arises because the server records the first two characters of a plaintext password at the beginning of the encrypted password. An attacker can exploit this weakness by launching brute force or dictionary attacks, making it easier to guess passwords with fewer attempts. This vulnerability poses a significant risk as it exposes a portion of the password, increasing the likelihood of unauthorized access. Attackers can potentially gain control over the server or steal sensitive information if successful. To mitigate this risk, users are advised to upgrade to a more secure version of the web server software or change their passwords to more complex and unique combinations.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share