Websense Reporter 'CreateDbInstall.log' Local Information Disclosure Vulnerability
BID:31746
Info
Websense Reporter 'CreateDbInstall.log' Local Information Disclosure Vulnerability
| Bugtraq ID: | 31746 |
| Class: | Design Error |
| CVE: |
CVE-2008-4646 |
| Remote: | No |
| Local: | Yes |
| Published: | Oct 13 2008 12:00AM |
| Updated: | May 07 2015 05:22PM |
| Credit: | Eric Beaulieu |
| Vulnerable: |
Websense Reporter 6.3.2 |
| Not Vulnerable: | |
Discussion
Websense Reporter 'CreateDbInstall.log' Local Information Disclosure Vulnerability
Websense Reporter is prone to a local information-disclosure vulnerability because it fails to securely store sensitive data.
Local attackers can exploit this issue to obtain the SQL administrator's login credentials.
Websense Reporter 6.3.2 is vulnerable; other versions may also be affected.
Websense Reporter is prone to a local information-disclosure vulnerability because it fails to securely store sensitive data.
Local attackers can exploit this issue to obtain the SQL administrator's login credentials.
Websense Reporter 6.3.2 is vulnerable; other versions may also be affected.
Exploit / POC
Websense Reporter 'CreateDbInstall.log' Local Information Disclosure Vulnerability
Attackers can exploit this issue using readily available tools.
Attackers can exploit this issue using readily available tools.
Solution / Fix
Websense Reporter 'CreateDbInstall.log' Local Information Disclosure Vulnerability
Solution:
Reports indicate that this issue has been addressed in Websense Reporter 7, but Symantec has not verified this information.
Solution:
Reports indicate that this issue has been addressed in Websense Reporter 7, but Symantec has not verified this information.
References
Websense Reporter 'CreateDbInstall.log' Local Information Disclosure Vulnerability
References:
References:
- Websense Homepage (Websense)