ContentKeeper Accounts Password Information Disclosure Vulnerability
BID:20152
Info
ContentKeeper Accounts Password Information Disclosure Vulnerability
| Bugtraq ID: | 20152 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Sep 22 2006 12:00AM |
| Updated: | Sep 22 2006 10:36PM |
| Credit: | Patrick Webster has been credited with the discovery of this vulnerability |
| Vulnerable: |
ContentKeeper Technologies ContentKeeper 123.25 |
| Not Vulnerable: | |
Discussion
ContentKeeper Accounts Password Information Disclosure Vulnerability
ContentKeeper is prone to a local information-disclosure vulnerability because the application fails to protect sensitive information to unprivileged users.
An authenticated attacker with user administrative permissions can exploit this issue to reveal authentication credentials from other user accounts. This information may be used to compromise other appliances and systems or assist on other attacks.
ContentKeeper 123.25 and prior versions are reported vulnerable to this issue.
ContentKeeper is prone to a local information-disclosure vulnerability because the application fails to protect sensitive information to unprivileged users.
An authenticated attacker with user administrative permissions can exploit this issue to reveal authentication credentials from other user accounts. This information may be used to compromise other appliances and systems or assist on other attacks.
ContentKeeper 123.25 and prior versions are reported vulnerable to this issue.
Exploit / POC
ContentKeeper Accounts Password Information Disclosure Vulnerability
An authenticated attacker with administrative permissions may exploit this issue by accessing the accounts management script and viewing its source.
An authenticated attacker with administrative permissions may exploit this issue by accessing the accounts management script and viewing its source.
Solution / Fix
ContentKeeper Accounts Password Information Disclosure Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
References
ContentKeeper Accounts Password Information Disclosure Vulnerability
References:
References:
- ContentKeeper Homepage (ContentKeeper)
- ContentKeeper Authenticated Access Password Disclosure (Patrick Webster)