Hobbit Monitor Logfetch Information Disclosure Vulnerability
BID:18752
CVE-2006-3373 |Info
Hobbit Monitor Logfetch Information Disclosure Vulnerability
| Bugtraq ID: | 18752 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Jun 30 2006 12:00AM |
| Updated: | Jul 04 2006 03:54PM |
| Credit: | The discoverer of this issue is currently not known. This issue was disclosed by the vendor. |
| Vulnerable: |
Hobbit Monitor Hobbit Monitor 4.2 |
| Not Vulnerable: | |
Discussion
Hobbit Monitor Logfetch Information Disclosure Vulnerability
Hobbit is prone to an information-disclosure vulnerability. This issue is due to a failure in the application to properly verify access to restricted information.
An attacker can exploit this issue to retrieve potentially sensitive information that may aid in further attacks.
Hobbit is prone to an information-disclosure vulnerability. This issue is due to a failure in the application to properly verify access to restricted information.
An attacker can exploit this issue to retrieve potentially sensitive information that may aid in further attacks.
Exploit / POC
Hobbit Monitor Logfetch Information Disclosure Vulnerability
An attacker can use the vulnerable application to exploit this issue.
An attacker can use the vulnerable application to exploit this issue.
Solution / Fix
Hobbit Monitor Logfetch Information Disclosure Vulnerability
Solution:
The vendor will be addressing this issue in the final 4.2 release.
Solution:
The vendor will be addressing this issue in the final 4.2 release.
References
Hobbit Monitor Logfetch Information Disclosure Vulnerability
References:
References:
- Hobbit Website (Hobbit)
- Hobbit monitor: Security issue with Hobbit 4.2-beta client ([email protected] (Henrik Stoerner))