SAFE TEAM Regulus Staffile Information Disclosure Vulnerability
BID:11132
Info
SAFE TEAM Regulus Staffile Information Disclosure Vulnerability
| Bugtraq ID: | 11132 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 07 2004 12:00AM |
| Updated: | Sep 07 2004 12:00AM |
| Credit: | Discovery of this vulnerability is credited to [email protected]. |
| Vulnerable: |
SAFE TEAM Regulus 2.2 -95 |
| Not Vulnerable: | |
Discussion
SAFE TEAM Regulus Staffile Information Disclosure Vulnerability
SAFE TEAM Regulus is reported prone to an information disclosure vulnerability. It is reported that any user may make a request for the Regulus 'staffile' file hosted on a target server. This file contains a list of Regulus 'staff' users and their corresponding password hashes.
An attacker may employ data that is obtained in this manner to aid in further attacks launched against the vulnerable software.
SAFE TEAM Regulus is reported prone to an information disclosure vulnerability. It is reported that any user may make a request for the Regulus 'staffile' file hosted on a target server. This file contains a list of Regulus 'staff' users and their corresponding password hashes.
An attacker may employ data that is obtained in this manner to aid in further attacks launched against the vulnerable software.
Exploit / POC
SAFE TEAM Regulus Staffile Information Disclosure Vulnerability
There is no exploit required; the following request is sufficient to exploit this vulnerability:
http://example.com/base-dir/access/stafffile
There is no exploit required; the following request is sufficient to exploit this vulnerability:
http://example.com/base-dir/access/stafffile
Solution / Fix
SAFE TEAM Regulus Staffile Information Disclosure Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
SAFE TEAM Regulus Staffile Information Disclosure Vulnerability
References:
References:
- REGULUS EXPOSED ([email protected])
- Regulus Homepage (SAFE TEAM)