COM2001 Alexis Server Plaintext Password Storage Vulnerability
BID:3372
Info
COM2001 Alexis Server Plaintext Password Storage Vulnerability
| Bugtraq ID: | 3372 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Sep 27 2001 12:00AM |
| Updated: | Sep 27 2001 12:00AM |
| Credit: | This vulnerability was submitted to BugTraq on September 27th, 2001 by Clint Byrum <[email protected]>. |
| Vulnerable: |
COM2001 Alexis Server 2.1 COM2001 Alexis Server 2.0 COM2001 Alexis Server 1.1 |
| Not Vulnerable: | |
Discussion
COM2001 Alexis Server Plaintext Password Storage Vulnerability
COM2001 Alexis Server is commercial voicemail/internet-based PBX management software for Microsoft Windows NT/2000 systems.
Alexis Server stores files in plaintext format in a file called 'com2001.ini', which is located in the root directory of the system running the software.
Successful exploitation of this issue will allow the local attacker to gain unauthorized access to voicemail and PBX services.
COM2001 Alexis Server is commercial voicemail/internet-based PBX management software for Microsoft Windows NT/2000 systems.
Alexis Server stores files in plaintext format in a file called 'com2001.ini', which is located in the root directory of the system running the software.
Successful exploitation of this issue will allow the local attacker to gain unauthorized access to voicemail and PBX services.
Exploit / POC
COM2001 Alexis Server Plaintext Password Storage Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
COM2001 Alexis Server Plaintext Password Storage Vulnerability
Solution:
The vendor is aware of this issue and will release a fix in an upcoming service pack.
Solution:
The vendor is aware of this issue and will release a fix in an upcoming service pack.
References
COM2001 Alexis Server Plaintext Password Storage Vulnerability
References:
References:
- Alexis Homepage (COM2001)