Beehive/SendFile.NET 'SendFile.jar' Insecure Default Account Unauthorized Access Vulnerability
BID:28060
Info
Beehive/SendFile.NET 'SendFile.jar' Insecure Default Account Unauthorized Access Vulnerability
| Bugtraq ID: | 28060 |
| Class: | Design Error |
| CVE: |
CVE-2008-1079 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 29 2008 12:00AM |
| Updated: | May 07 2015 05:32PM |
| Credit: | Brad Antoniewicz disclosed this issue. |
| Vulnerable: |
Beehive Software Beehive/SendFile.NET 0 |
| Not Vulnerable: | |
Discussion
Beehive/SendFile.NET 'SendFile.jar' Insecure Default Account Unauthorized Access Vulnerability
Beehive/SendFile.NET is prone to a vulnerability that can result in unauthorized access. The issue occurs because of an insecure default account in 'SendFile.jar'.
Successfully exploiting this issue allows remote attackers to gain access to the database and to execute arbitrary code with the privileges of the database user. This may aid in the remote compromise of affected computers.
Beehive/SendFile.NET is prone to a vulnerability that can result in unauthorized access. The issue occurs because of an insecure default account in 'SendFile.jar'.
Successfully exploiting this issue allows remote attackers to gain access to the database and to execute arbitrary code with the privileges of the database user. This may aid in the remote compromise of affected computers.
Exploit / POC
Beehive/SendFile.NET 'SendFile.jar' Insecure Default Account Unauthorized Access Vulnerability
An attacker can exploit this issue via a browser or FTP client.
An attacker can exploit this issue via a browser or FTP client.
Solution / Fix
Beehive/SendFile.NET 'SendFile.jar' Insecure Default Account Unauthorized Access Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Beehive/SendFile.NET 'SendFile.jar' Insecure Default Account Unauthorized Access Vulnerability
References:
References: