Zixforum ZixForum.mdb Database Disclosure Vulnerability
BID:10982
Info
Zixforum ZixForum.mdb Database Disclosure Vulnerability
| Bugtraq ID: | 10982 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 19 2004 12:00AM |
| Updated: | Aug 19 2004 12:00AM |
| Credit: | Discovery is credited to "Security .Net Information" <[email protected]>. |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Zixforum ZixForum.mdb Database Disclosure Vulnerability
Zixforum is reported prone to a database disclosure vulnerability. It is reported that remote users may download the database file ''ZixForum.mdb' and gain access to sensitive information including unencrypted authentication credentials.
All versions of Zixforum are considered vulnerable to this issue.
This issue is being retired due to the fact that this is not a vulnerability in the application. Configuring the Web server to restrict access to sensitive files can prevent this problem.
Zixforum is reported prone to a database disclosure vulnerability. It is reported that remote users may download the database file ''ZixForum.mdb' and gain access to sensitive information including unencrypted authentication credentials.
All versions of Zixforum are considered vulnerable to this issue.
This issue is being retired due to the fact that this is not a vulnerability in the application. Configuring the Web server to restrict access to sensitive files can prevent this problem.
Exploit / POC
Zixforum ZixForum.mdb Database Disclosure Vulnerability
No exploit is required.
The following proof of concept is available:
http://www.example.com/forum/ZixForum.mdb
No exploit is required.
The following proof of concept is available:
http://www.example.com/forum/ZixForum.mdb
Solution / Fix
Zixforum ZixForum.mdb Database Disclosure Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Zixforum ZixForum.mdb Database Disclosure Vulnerability
References:
References: