Password Vulnerability in Excite for Web Servers (EWS) 1.1: Weak Encryption Scheme Allows for Password Guessing

Password Vulnerability in Excite for Web Servers (EWS) 1.1: Weak Encryption Scheme Allows for Password Guessing

CVE-1999-1073 · HIGH Severity

AV:L/AC:L/AU:N/C:C/I:C/A:C

Excite for Web Servers (EWS) 1.1 records the first two characters of a plaintext password in the beginning of the encrypted password, which makes it easier for an attacker to guess passwords via a brute force or dictionary attack.

Learn more about our Web App Pen Testing.