Kolab Groupware Server Apache Log File User Password Information Disclosure Vulnerability
BID:31165
Info
Kolab Groupware Server Apache Log File User Password Information Disclosure Vulnerability
| Bugtraq ID: | 31165 |
| Class: | Design Error |
| CVE: |
CVE-2008-4165 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 13 2008 12:00AM |
| Updated: | May 07 2015 05:24PM |
| Credit: | Gavin McCullagh of Griffith College Dublin |
| Vulnerable: |
MandrakeSoft Corporate Server 3.0 x86_64 MandrakeSoft Corporate Server 3.0 Kolab Kolab Groupware Server 1.0.8 Kolab Kolab Groupware Server 1.0.7 Kolab Kolab Groupware Server 1.0.6 Kolab Kolab Groupware Server 1.0.5 Kolab Kolab Groupware Server 1.0.3 Kolab Kolab Groupware Server 1.0.1 Kolab Kolab Groupware Server 1.0 -20040426 Kolab Kolab Groupware Server 1.0 |
| Not Vulnerable: | |
Discussion
Kolab Groupware Server Apache Log File User Password Information Disclosure Vulnerability
Kolab Groupware Server is prone to an information-disclosure vulnerability.
Attackers can exploit this issue to gain access to sensitive information. Information obtained may lead to other attacks.
Kolab Groupware Server is prone to an information-disclosure vulnerability.
Attackers can exploit this issue to gain access to sensitive information. Information obtained may lead to other attacks.
Exploit / POC
Kolab Groupware Server Apache Log File User Password Information Disclosure Vulnerability
Attackers can exploit this issue through a web browser.
Attackers can exploit this issue through a web browser.
Solution / Fix
Kolab Groupware Server Apache Log File User Password Information Disclosure Vulnerability
Solution:
Updates are available to address this issue. Please see the references for more information.
MandrakeSoft Corporate Server 3.0 x86_64
MandrakeSoft Corporate Server 3.0
Solution:
Updates are available to address this issue. Please see the references for more information.
MandrakeSoft Corporate Server 3.0 x86_64
-
Mandriva kolab-server-1.0-0.24.C30mdk.x86_64.rpm
http://www.mandriva.com/en/download/
MandrakeSoft Corporate Server 3.0
-
Mandriva kolab-server-1.0-0.24.C30mdk.i586.rpm
http://www.mandriva.com/en/download/
References
Kolab Groupware Server Apache Log File User Password Information Disclosure Vulnerability
References:
References:
- Vendor Homepage (Kolab)
- Mandriva Bugzilla Bug Bugzilla �?? Bug 43434 (Mandriva)