Ozeki HTTP-SMS Gateway Password Information Disclosure Vulnerability
BID:21679
Info
Ozeki HTTP-SMS Gateway Password Information Disclosure Vulnerability
| Bugtraq ID: | 21679 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Dec 20 2006 12:00AM |
| Updated: | Dec 20 2006 09:32PM |
| Credit: | Basher13 is credited with the discovery of this vulnerability |
| Vulnerable: |
Ozeki NG SMS Gateway Software 1.0 |
| Not Vulnerable: | |
Discussion
Ozeki HTTP-SMS Gateway Password Information Disclosure Vulnerability
Ozeki HTTP-SMS Gateway is prone to a local information-disclosure vulnerability because the application fails to protect sensitive information from unprivileged users.
A local attacker can exploit this issue to access sensitive information. This may lead to other attacks.
This issue affects version 1.0; other versions may also be affected.
Ozeki HTTP-SMS Gateway is prone to a local information-disclosure vulnerability because the application fails to protect sensitive information from unprivileged users.
A local attacker can exploit this issue to access sensitive information. This may lead to other attacks.
This issue affects version 1.0; other versions may also be affected.
Exploit / POC
Ozeki HTTP-SMS Gateway Password Information Disclosure Vulnerability
An attacker can exploit this issue by gaining local interactive access to the computer hosting the vulnerable application.
An attacker can exploit this issue by gaining local interactive access to the computer hosting the vulnerable application.
Solution / Fix
Ozeki HTTP-SMS Gateway Password Information Disclosure Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
References
Ozeki HTTP-SMS Gateway Password Information Disclosure Vulnerability
References:
References:
- Ozeki NG SMS Gateway Software Home Page (Ozeki NG )