CVE detail
CVE-2002-2046 — CVE-2002-2046
Published 2002-12-31 · Modified 2026-06-16 · Vendor xqus · Product x-news · Source nvd
UNKNOWN
severity
CVSS-derived band
0.0132
EPSS probability
exploitation probability, 30d
68.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
x_news.php in X-News (x_news) 1.1 and earlier allows remote attackers to gain administrative privileges by stealing and replaying the md5_password cookie.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References