iMatix Xitami Administrator Plain Text Password Storage Vulnerability
BID:3582
Info
iMatix Xitami Administrator Plain Text Password Storage Vulnerability
| Bugtraq ID: | 3582 |
| Class: | Configuration Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Nov 26 2001 12:00AM |
| Updated: | Nov 26 2001 12:00AM |
| Credit: | Discovered and posted to Bugtraq by Larry W. Cashdollar <[email protected]>. |
| Vulnerable: |
Imatix Xitami 2.5 b4 Imatix Xitami 2.5 Imatix Xitami 2.4 |
| Not Vulnerable: | |
Discussion
iMatix Xitami Administrator Plain Text Password Storage Vulnerability
An issue has been reported in Xitami that may result in the disclosure of admin authentication information.
If a local user gained access to the 'default.aut' file, it is possible to retrieve administrator authentication information for Xitami. By default the contents of this file are in plain text and the file is world readable and writable.
It should be noted that the plain text admin credentials is documented in the Xitami FAQ. See reference section for more details.
An issue has been reported in Xitami that may result in the disclosure of admin authentication information.
If a local user gained access to the 'default.aut' file, it is possible to retrieve administrator authentication information for Xitami. By default the contents of this file are in plain text and the file is world readable and writable.
It should be noted that the plain text admin credentials is documented in the Xitami FAQ. See reference section for more details.
Exploit / POC
iMatix Xitami Administrator Plain Text Password Storage Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
iMatix Xitami Administrator Plain Text Password Storage Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
iMatix Xitami Administrator Plain Text Password Storage Vulnerability
References:
References:
- Xitami FAQ (Imatix)
- Xitami Homepage (iMatix)