CVE-2003-1394

CoffeeCup Software Password Wizard 4.0 stores sensitive information such as usernames and passwords in a .apw file under the web document root with insufficient access control, which allows remote attackers to obtain that information via a direct request for the file.

Scoring

CVSS base score
0.01
EPSS probability
0.29%
Published
2007-10-19
Last modified
2026-03-16

Affected products

Markdown version · Browse all CVEs