CVE-2002-2190 EXPLOIT
7.5
HIGH · CVSS 2.0 · EPSS 6.7% (pctl 94)
Patch early
A public exploit exists.
Description
ArtsCore Studios CuteCast Forum 1.2 stores passwords in plaintext under the web document root, which allows remote attackers to obtain the passwords via an HTTP request to a .user file.
Scoring
| CVSS | 7.5 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 6.69% — more likely to be exploited than 94% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2002-12-31 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| artscore studios | cutecast forum |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | CuteCast 1.2 - User Credential Disclosure | 2002-11-07 |
References
- http://archives.neohapsis.com/archives/bugtraq/2002-11/0058.html
- http://www.iss.net/security_center/static/10556.php
- http://www.securityfocus.com/bid/6127
- http://archives.neohapsis.com/archives/bugtraq/2002-11/0058.html
- http://www.iss.net/security_center/static/10556.php
- http://www.securityfocus.com/bid/6127
→ the Explorer · watch your stack · NVD