Default Group Account with No Password in Akopia Interchange Demo Stores

Default Group Account with No Password in Akopia Interchange Demo Stores

CVE-2001-0372 · HIGH Severity

AV:N/AC:L/AU:N/C:C/I:C/A:C

Akopia Interchange 4.5.3 through 4.6.3 installs demo stores with a default group account :backup with no password, which allows a remote attacker to gain administrative access via the demo stores (1) barry, (2) basic, or (3) construct.

Learn more about our Web Application Penetration Testing UK.