CyberRota
Live Feed
Return to register
Case File

CVE-2002-0286

HIGH · CVSS 7.5 EPSS 1.57%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2002-05-31 · Last synced 2026-08-04

Field Assessment

AI analysis pending.

CVE
CVE-2002-0286
Severity
HIGH
CVSS
7.5
EPSS
1.57%

Original Filing — NVD Description

The GetPassword function in function.php of SiteNews 0.10 and 0.11 allows remote attackers to gain privileges and add users by providing a non-existent user name and the MD5 checksum for an empty password to add_user.php, which causes GetPassword to produce and compare a blank password for the non-existent user.