CWE-258 - Empty Password in Configuration File
CWE-258 High
- Abstraction:
- Variant
- Structure:
- Simple
- Status:
- Incomplete
- Weakness Name
Empty Password in Configuration File
- Description
Using an empty string as a password is insecure.
- Common Consequences
Scope: Access Control
Impact: Gain Privileges or Assume Identity
- Related Weaknesses
- Release Date:
- 2006-07-19
- Latest Modification Date:
- 2023-10-26
Latest Security News
Top Alert List
MediumDirectory Browsing
InformationalInformation Disclosure - Suspicious Comments
InformationalModern Web Application
Top CWE List
Free security scan for your website