Prolog Manager Insecure Encryption Username and Password Information Disclosure Vulnerability
BID:26826
Info
Prolog Manager Insecure Encryption Username and Password Information Disclosure Vulnerability
| Bugtraq ID: | 26826 |
| Class: | Design Error |
| CVE: |
CVE-2007-6330 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 11 2007 12:00AM |
| Updated: | Jan 11 2008 04:39AM |
| Credit: | The reporter of this issue wishes to remain anonymous. |
| Vulnerable: |
Meridian Software Prolog Manager 7.5 Meridian Software Prolog Manager 7.0 Meridian Software Prolog Manager 2007 |
| Not Vulnerable: | |
Discussion
Prolog Manager Insecure Encryption Username and Password Information Disclosure Vulnerability
Prolog Manager is prone to a vulnerability that allows users to gain unauthorized access to the affected application. This issue occurs when the application sends sensitive data through an insecure channel.
An attacker can exploit this issue to obtain sensitive information and possibly gain unauthorized access to the affected application. Other attacks are also possible.
Prolog Manager is prone to a vulnerability that allows users to gain unauthorized access to the affected application. This issue occurs when the application sends sensitive data through an insecure channel.
An attacker can exploit this issue to obtain sensitive information and possibly gain unauthorized access to the affected application. Other attacks are also possible.
Exploit / POC
Prolog Manager Insecure Encryption Username and Password Information Disclosure Vulnerability
An attacker can exploit this issue by using readily available network utilities and brute-force techniques.
An attacker can exploit this issue by using readily available network utilities and brute-force techniques.
Solution / Fix
Prolog Manager Insecure Encryption Username and Password Information Disclosure Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Prolog Manager Insecure Encryption Username and Password Information Disclosure Vulnerability
References:
References:
- Product Tip of the Month �?? Prolog (Meridian Systems)
- Prolog Manager Homepage (Meridian Software)
- Meridian Prolog Manager Username and Plain Text Password Disclosure ('Prolog Error'
) - Vulnerability Note VU#120593 Prolog Manager uses weak authentication to store au (US-CERT)