AppServ Open Project Remote Insecure Default Password Vulnerability
BID:11704
Info
AppServ Open Project Remote Insecure Default Password Vulnerability
| Bugtraq ID: | 11704 |
| Class: | Configuration Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 18 2004 12:00AM |
| Updated: | Nov 18 2004 12:00AM |
| Credit: | Discovery of this issue is credited to saudi linux <[email protected]>. |
| Vulnerable: |
AppServ Open Project 2.5.2 AppServ Open Project 2.5.1 AppServ Open Project 2.5 AppServ Open Project 2.4.2 AppServ Open Project 2.4.1 AppServ Open Project 2.4 |
| Not Vulnerable: | |
Discussion
AppServ Open Project Remote Insecure Default Password Vulnerability
A remote insecure default password vulnerability reportedly affects AppServ Open Project. This issue is due to a failure of the application to securely create a default user account on the installed database.
An attacker may leverage this issue to gain access to the MySQL database through the insecure user account installed by the affected application. This may facilitate unauthorized access or privilege escalation.
A remote insecure default password vulnerability reportedly affects AppServ Open Project. This issue is due to a failure of the application to securely create a default user account on the installed database.
An attacker may leverage this issue to gain access to the MySQL database through the insecure user account installed by the affected application. This may facilitate unauthorized access or privilege escalation.
Exploit / POC
AppServ Open Project Remote Insecure Default Password Vulnerability
No exploit is required to leverage this issue.
No exploit is required to leverage this issue.
Solution / Fix
AppServ Open Project Remote Insecure Default Password Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
AppServ Open Project Remote Insecure Default Password Vulnerability
References:
References:
- AppServ Open Project Home Page (AppServ Open Project)
- AppServ 2.5.x and Prior Exploit (saudi linux
)