Netenberg Fantastico De Luxe Predictable Username Brute Force Vulnerability
BID:10390
Info
Netenberg Fantastico De Luxe Predictable Username Brute Force Vulnerability
| Bugtraq ID: | 10390 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | May 19 2004 12:00AM |
| Updated: | May 19 2004 12:00AM |
| Credit: | This issue was disclosed by Michael Curtis <[email protected]>. |
| Vulnerable: |
Netenberg Fantastico De Luxe 2.8 |
| Not Vulnerable: | |
Discussion
Netenberg Fantastico De Luxe Predictable Username Brute Force Vulnerability
Fantastico De Luxe is prone to a vulnerability that could allow an attacker to brute force user accounts and potentially gain unauthorized access. This issue presents itself when the application is used in combination with a MySQL database. The vulnerability occurs when Fantastico De Luxe creates database files for users by using valid user names.
Successful exploitation of this issue can allow an attacker to ultimately gain access to user credentials and therefore potentially gain access to accounts.
Fantastico De Luxe is prone to a vulnerability that could allow an attacker to brute force user accounts and potentially gain unauthorized access. This issue presents itself when the application is used in combination with a MySQL database. The vulnerability occurs when Fantastico De Luxe creates database files for users by using valid user names.
Successful exploitation of this issue can allow an attacker to ultimately gain access to user credentials and therefore potentially gain access to accounts.
Exploit / POC
Netenberg Fantastico De Luxe Predictable Username Brute Force Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
Netenberg Fantastico De Luxe Predictable Username Brute Force Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Netenberg Fantastico De Luxe Predictable Username Brute Force Vulnerability
References:
References:
- Fantastico De Luxe Product Page (Netenberg)
- Non-logged Brute Force Attack Vulnerability for Fantastico-Created Databases on ("Michael Curtis"
)