AuditWizard Log File Information Disclosure Vulnerability
BID:19860
CVE-2006-4642 |Info
AuditWizard Log File Information Disclosure Vulnerability
| Bugtraq ID: | 19860 |
| Class: | Design Error |
| CVE: |
CVE-2006-4642 |
| Remote: | No |
| Local: | Yes |
| Published: | Sep 05 2006 12:00AM |
| Updated: | Jul 06 2016 01:32PM |
| Credit: | Terry Donaldson is credited with discovering this vulnerability. |
| Vulnerable: |
Layton Technology AuditWizard 6.3.2 |
| Not Vulnerable: | |
Discussion
AuditWizard Log File Information Disclosure Vulnerability
AuditWizard is prone to an information-disclosure vulnerability because the application fails to properly ensure that sensitive information is not disclosed to local users.
This issue allows local attackers to gain access to sensitive administrative account-authentication credentials.
Reportedly, the vendor may have reissued version 6.3.2 with fixes that address this issue; Symantec has not confirmed this.
AuditWizard is prone to an information-disclosure vulnerability because the application fails to properly ensure that sensitive information is not disclosed to local users.
This issue allows local attackers to gain access to sensitive administrative account-authentication credentials.
Reportedly, the vendor may have reissued version 6.3.2 with fixes that address this issue; Symantec has not confirmed this.
Exploit / POC
AuditWizard Log File Information Disclosure Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]
Solution / Fix
AuditWizard Log File Information Disclosure Vulnerability
Solution:
Reportedly, the vendor may have reissued version 6.3.2 to address this issue; Symantec has not confirmed this.
Please contact the vendor for more information.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Reportedly, the vendor may have reissued version 6.3.2 to address this issue; Symantec has not confirmed this.
Please contact the vendor for more information.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
AuditWizard Log File Information Disclosure Vulnerability
References:
References:
- Layton Technology Homepage (Layton Technology)
- AuditWizard 6.3.2 gives away administrator password (Terry Donaldson)