Netwin WebNews 1.1k CGI program includes several default usernames and cleartext passwords that cannot be deleted by the administrator, which allows remote attackers to gain privileges via the username/password combinations (1) testweb/newstest, (2) alwn3845/imaptest, (3) alwi3845/wtest3452, or (4) testweb2/wtest4879.
| Software | From | Fixed in |
|---|---|---|
| netwin / webnews | 1.1i | 1.1i.x |
| netwin / webnews | 1.1h | 1.1h.x |
| netwin / webnews | 1.1j | 1.1j.x |
| netwin / webnews | 1.1k | 1.1k.x |