CWE-258 - Empty Password in Configuration File
CWE-258 High
- Abstraction:
- Variant
- Structure:
- Simple
- Status:
- Incomplete
- Weakness Name
Empty Password in Configuration File
- Description
Using an empty string as a password is insecure.
- Common Consequences
Scope: Access Control
Impact: Gain Privileges or Assume Identity
- Related Weaknesses
- Release Date:
- 2006-07-19
- Latest Modification Date:
- 2023-10-26
Top Security News
Common Alerts
InformationalCross Site Scripting (Persistent) - Prime
InformationalSec-Fetch-Dest Header is Missing
Top CVE List
Top CWE List
Free security scan for your website