Unrated severityNVD Advisory· Published Feb 16, 2001· Updated Apr 16, 2026
CVE-2001-0088
CVE-2001-0088
Description
common.inc.php in phpWebLog 0.4.2 does not properly initialize the $CONF array, which inadvertently sets the password to a single character, allowing remote attackers to easily guess the SiteKey and gain administrative privileges to phpWebLog.
Affected products
1- cpe:2.3:a:jason_hines:phpweblog:0.4.2:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- archives.neohapsis.com/archives/bugtraq/2000-12/0025.htmlnvdExploitVendor Advisory
- www.securityfocus.com/bid/2047nvdExploitVendor Advisory
- exchange.xforce.ibmcloud.com/vulnerabilities/5625nvd
News mentions
0No linked articles in our index yet.