Synopsis
A web application is protected using default administrative credentials.
Description
The remote WebTitan web interface uses a default set of credentials ('admin' / 'hiadmin') to control access to its management interface. A remote, unauthenticated attacker could exploit this to log in as a privileged user and gain administrative access to the application.
Solution
Log into the application and change the default login credentials.
Plugin Details
File Name: webtitan_frontend_default_credentials.nasl
Supported Sensors: Nessus
Vulnerability Information
CPE: cpe:/a:webtitan:webtitan
Required KB Items: www/webtitan
Excluded KB Items: global_settings/supplied_logins_only