CVE-2002-0286

The GetPassword function in function.php of SiteNews 0.10 and 0.11 allows remote attackers to gain privileges and add users by providing a non-existent user name and the MD5 checksum for an empty password to add_user.php, which causes GetPassword to produce and compare a blank password for the non-existent user.

Scoring

CVSS base score
0.03
EPSS probability
0.72%
Published
2002-05-03
Last modified
2026-03-16

Affected products

Markdown version · Browse all CVEs