SAFE TEAM Regulus Custchoice.PHP Update Your Password Action Information Disclosure Vulnerability
BID:11133
Info
SAFE TEAM Regulus Custchoice.PHP Update Your Password Action Information Disclosure Vulnerability
| Bugtraq ID: | 11133 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 07 2004 12:00AM |
| Updated: | Sep 07 2004 12:00AM |
| Credit: | Discovery of this vulnerability is credited to [email protected]. |
| Vulnerable: |
SAFE TEAM Regulus 2.2 -95 |
| Not Vulnerable: | |
Discussion
SAFE TEAM Regulus Custchoice.PHP Update Your Password Action Information Disclosure Vulnerability
Regulus is reported prone to an information disclosure vulnerability. It is reported that a specified user/customer password hash is contained in a hidden tag of the 'Update Your Password' action page.
An attacker may employ data that is obtained in this manner to aid in further attacks launched against the vulnerable software.
This vulnerability is reported to affect all versions of SAFE TEAM Regulus.
Regulus is reported prone to an information disclosure vulnerability. It is reported that a specified user/customer password hash is contained in a hidden tag of the 'Update Your Password' action page.
An attacker may employ data that is obtained in this manner to aid in further attacks launched against the vulnerable software.
This vulnerability is reported to affect all versions of SAFE TEAM Regulus.
Exploit / POC
SAFE TEAM Regulus Custchoice.PHP Update Your Password Action Information Disclosure Vulnerability
There is no exploit required; the following request is sufficient to exploit this vulnerability:
http://example.com/base-dir/htmlcust/custchoice.php?lang=English&userid=<name>&action=To update your password
Where '<name>' is the target username.
There is no exploit required; the following request is sufficient to exploit this vulnerability:
http://example.com/base-dir/htmlcust/custchoice.php?lang=English&userid=<name>&action=To update your password
Where '<name>' is the target username.
Solution / Fix
SAFE TEAM Regulus Custchoice.PHP Update Your Password Action Information Disclosure Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
SAFE TEAM Regulus Custchoice.PHP Update Your Password Action Information Disclosure Vulnerability
References:
References:
- REGULUS EXPOSED ([email protected])
- Regulus Homepage (SAFE TEAM)