Excite for Web Servers (EWS) 1.1 records the first two characters of a plaintext password in the beginning of the encrypted password, which makes it easier for an attacker to guess passwords via a brute force or dictionary attack.
| Software | From | Fixed in |
|---|---|---|
| excite / ews | 1.1 | 1.1.x |