Discus bad default permissions Vulnerability
BID:141
Info
Discus bad default permissions Vulnerability
| Bugtraq ID: | 141 |
| Class: | Configuration Error |
| CVE: | |
| Remote: | Yes |
| Local: | Yes |
| Published: | Apr 23 1999 12:00AM |
| Updated: | Apr 23 1999 12:00AM |
| Credit: | This vulnerability was reported by elaich <[email protected]> to the Bugtraq mailing list. |
| Vulnerable: |
DiscusWare Discus 3.1.1 |
| Not Vulnerable: | |
Discussion
Discus bad default permissions Vulnerability
Discus if a free WWW discussion board software package. The default configuration sets up a number of file with to broad permissions. These files include those with user passwords (passwd.txt). The installtion script determines what permissions to assign files by looking at the "filelist.txt" file. A local user could obtain read access to these files and crack the users passwords.
Discus if a free WWW discussion board software package. The default configuration sets up a number of file with to broad permissions. These files include those with user passwords (passwd.txt). The installtion script determines what permissions to assign files by looking at the "filelist.txt" file. A local user could obtain read access to these files and crack the users passwords.
Exploit / POC
Discus bad default permissions Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Discus bad default permissions Vulnerability
Solution:
Remote the world read and writer permissions from the files in the discuss_admin directory. Make sure the user under which the CGI runs under can access them.
Solution:
Remote the world read and writer permissions from the files in the discuss_admin directory. Make sure the user under which the CGI runs under can access them.
References
Discus bad default permissions Vulnerability
References:
References: