deltathree PC-to-Phone Authentication Information Disclosure Vulnerability
BID:3475
Info
deltathree PC-to-Phone Authentication Information Disclosure Vulnerability
| Bugtraq ID: | 3475 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Oct 25 2001 12:00AM |
| Updated: | Oct 25 2001 12:00AM |
| Credit: | Discovered and posted to Bugtraq by Arthur Hagen <[email protected]> Oct 25, 2001. |
| Vulnerable: |
deltathree PC-to-Phone 3.0.3 |
| Not Vulnerable: | |
Discussion
deltathree PC-to-Phone Authentication Information Disclosure Vulnerability
PC-to-Phone is an application which enables a user to make PC to telephone or PC to PC calls using IP telephony services. PC-to-Phone is maintained by iConnectHere and powered by deltathree.
An issue exists with PC-to-Phone which could lead to the disclosure of confidential PC-to-Phone authentication information.
If a user on a multiuser-system successfully viewed the contents of the 'temp.html' file, the contents would reveal the account number and password information of a currently logged in user. This file is world readable.
PC-to-Phone is an application which enables a user to make PC to telephone or PC to PC calls using IP telephony services. PC-to-Phone is maintained by iConnectHere and powered by deltathree.
An issue exists with PC-to-Phone which could lead to the disclosure of confidential PC-to-Phone authentication information.
If a user on a multiuser-system successfully viewed the contents of the 'temp.html' file, the contents would reveal the account number and password information of a currently logged in user. This file is world readable.
References
deltathree PC-to-Phone Authentication Information Disclosure Vulnerability
References:
References:
- PC-to-Phone Homepage (deltathree)