FREEze Greetings 'pwd.txt' Password Information Disclosure Vulnerability
BID:32325
Info
FREEze Greetings 'pwd.txt' Password Information Disclosure Vulnerability
| Bugtraq ID: | 32325 |
| Class: | Design Error |
| CVE: |
CVE-2008-5218 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 17 2008 12:00AM |
| Updated: | May 07 2015 05:21PM |
| Credit: | cOndemned |
| Vulnerable: |
ScriptsEZ.net FREEze Greetings 1.0 |
| Not Vulnerable: | |
Discussion
FREEze Greetings 'pwd.txt' Password Information Disclosure Vulnerability
FREEze Greetings is prone to an information-disclosure vulnerability because it fails to sanitize user-supplied input before using it to provide authentication credentials.
Attackers can exploit this issue to obtain sensitive information that may lead to further attacks.
FREEze Greetings is prone to an information-disclosure vulnerability because it fails to sanitize user-supplied input before using it to provide authentication credentials.
Attackers can exploit this issue to obtain sensitive information that may lead to further attacks.
Exploit / POC
FREEze Greetings 'pwd.txt' Password Information Disclosure Vulnerability
To exploit this issue, attackers can use readily available commands or network utilities.
The following exploit code is available:
To exploit this issue, attackers can use readily available commands or network utilities.
The following exploit code is available:
Solution / Fix
FREEze Greetings 'pwd.txt' Password Information Disclosure Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
FREEze Greetings 'pwd.txt' Password Information Disclosure Vulnerability
References:
References:
- FreezeGreetings Homepage (Scriptez)