Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
NetWin Authentication module (NWAuth) 2.0 and 3.0b, as implemented in SurgeFTP, DMail, and possibly other packages, uses weak password hashing, which could allow local users to decrypt passwords or use a different password that has the same hash value as the correct password.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Netwin NWAuth 脆弱密码加密漏洞
Vulnerability Description
CVE(CAN) ID: CAN-2001-1354 NWAuth是Netwin的外部认证模块,被好几个Netwin的产品所采用。 NWAuth使用了一个简单的单向HASH函数对密码进行加密,因此攻击者很容易对这些密码 进行解密。
CVSS Information
N/A
Vulnerability Type
N/A