WebTrends Enterprise Reporting...

- AV AC AU C I A
发布: 1999-10-09
修订: 2025-04-13

Certain versions of the WebTrends Enterprise Reporting Server contain a series of vulnerabilities. Namely versions 1.5 and previous, the vulnerabilities in question are: 1. Logging via the server will write to a world/writable file. Under certain conditions this file may contain certain sensitive information such as usernames and passwords, in clear text. This in particular is known to occur if you are not running using PAM (Pluggable Authentication Module). If the server is running without PAM, users must use the server provided interface to create new users and set their passwords. In this case, by default, everything (including username and password) is stored in clear text in the file "interface.log" with read/write permissions for user, group and other. Any local user can read that file. If a WebTrends user has also an shell account on the box with the same password, that account can be compromised. 2. The server stores its' user information in files with world read/write...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息