Back
CVE-2005-3435
CRITICAL
admin_news.php in Archilles Newsworld up to 1.3.0 allows attackers to bypass authentication by obtaining the password hash for another user, for example through another Newsworld vulnerability, and specifying the hash in the pwd argument.
Published: Nov 2, 2005
Modified: Jun 16, 2026
CWE-522
CVSS Metrics
CVSSv3
Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
HIGH
Availability Impact:
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products (1)
| Vendor | Product | Version |
|---|---|---|
| archilles | newsworld | * |
GitHub Security Advisory GHSA-827j-q3cq-7j37
admin_news.php in Archilles Newsworld up to 1.3.0 allows attackers to bypass authentication by...
References (6)
- http://marc.info/?l=bugtraq&m=113018731120709&w=2 Mailing List
- http://secunia.com/advisories/17310/ Broken Link, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/22860 Third Party Advisory, VDB Entry
- http://marc.info/?l=bugtraq&m=113018731120709&w=2 Mailing List
- http://secunia.com/advisories/17310/ Broken Link, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/22860 Third Party Advisory, VDB Entry
Risk Scores
CVSS Score
9.8 / 10
EPSS Score
2.33%
Top 18% most likely to be exploited
Threat Score
39.9 / 100
Data Sources
NVD
EPSS
GitHub