Hobbit Monitor Config Information Disclosure Vulnerability
BID:19317
CVE-2006-4003 |Info
Hobbit Monitor Config Information Disclosure Vulnerability
| Bugtraq ID: | 19317 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 02 2006 12:00AM |
| Updated: | Aug 03 2006 08:16PM |
| Credit: | Jason Kruse has been credited with the discovery of this vulnerability. |
| Vulnerable: |
Hobbit Monitor Hobbit Monitor 4.1.2p1 Hobbit Monitor Hobbit Monitor 4.1 Hobbit Monitor Hobbit Monitor 4.0 |
| Not Vulnerable: |
Hobbit Monitor Hobbit Monitor 4.1.2p2 |
Discussion
Hobbit Monitor Config Information Disclosure Vulnerability
Hobbit is prone to an information-disclosure vulnerability because it fails to properly verify access to restricted information.
An attacker can exploit this issue to retrieve potentially sensitive information that may aid in further attacks.
Versions 4.0 to 4.1.2p1 are vulnerable to this issue.
Hobbit is prone to an information-disclosure vulnerability because it fails to properly verify access to restricted information.
An attacker can exploit this issue to retrieve potentially sensitive information that may aid in further attacks.
Versions 4.0 to 4.1.2p1 are vulnerable to this issue.
Exploit / POC
Hobbit Monitor Config Information Disclosure Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
Hobbit Monitor Config Information Disclosure Vulnerability
Solution:
The vendor has released version 4.1.2p2 to address this issue. Please see the references for more information.
Solution:
The vendor has released version 4.1.2p2 to address this issue. Please see the references for more information.
References
Hobbit Monitor Config Information Disclosure Vulnerability
References:
References: