Minihttp Forum Web Server Plain Text Password Storage Vulnerability
BID:11585
Info
Minihttp Forum Web Server Plain Text Password Storage Vulnerability
| Bugtraq ID: | 11585 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Nov 02 2004 12:00AM |
| Updated: | Nov 02 2004 12:00AM |
| Credit: | Disclosure of this issue is credited to R00tCr4ck <[email protected]>. |
| Vulnerable: |
Minihttp WebForum Server 2.0 Minihttp WebForum Server 1.6 Minihttp WebForum Server 1.5 Minihttp WebForum Server 1.0 |
| Not Vulnerable: | |
Discussion
Minihttp Forum Web Server Plain Text Password Storage Vulnerability
Minihttp Web Forum Server is reportedly affected by plain text password storage vulnerability. This issue is due to a design error.
An attacker may leverage this issue to reveal the plaintext authentication credentials of all users registered with the server.
Minihttp Web Forum Server is reportedly affected by plain text password storage vulnerability. This issue is due to a design error.
An attacker may leverage this issue to reveal the plaintext authentication credentials of all users registered with the server.
Exploit / POC
Minihttp Forum Web Server Plain Text Password Storage Vulnerability
No exploit is required to leverage this issue.
No exploit is required to leverage this issue.
Solution / Fix
Minihttp Forum Web Server Plain Text Password Storage Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Minihttp Forum Web Server Plain Text Password Storage Vulnerability
References:
References:
- Forum Web Server Home Page (Minihttp)
- Multiple Vulnerabilities in Web Forums Server (R00tCr4ck
)