Alchemy Remote Network Log Viewing Vulnerability
BID:3598
Info
Alchemy Remote Network Log Viewing Vulnerability
| Bugtraq ID: | 3598 |
| Class: | Access Validation Error |
| CVE: |
CVE-2001-0870 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 29 2001 12:00AM |
| Updated: | Jul 11 2009 09:06AM |
| Credit: | This vulnerability was announced in a Rapid 7 Advisory posted to Bugtraq on November 30, 2001. |
| Vulnerable: |
Alchemy Lab Alchemy Eye 2.6.18 Alchemy Lab Alchemy Eye 2.6 Alchemy Lab Alchemy Eye 2.5 Alchemy Lab Alchemy Eye 2.4 Alchemy Lab Alchemy Eye 2.3 Alchemy Lab Alchemy Eye 2.2 Alchemy Lab Alchemy Eye 2.1 Alchemy Lab Alchemy Eye 2.0 Alchemy Lab Alchemy Eye 1.9 |
| Not Vulnerable: |
Alchemy Lab Alchemy Eye 3.0 Alchemy Lab Alchemy Eye 2.6.19 |
Discussion
Alchemy Remote Network Log Viewing Vulnerability
Alchemy is a Eye and Alchemy Network Monitor are both products based off the Alchemy Eye network management and server monitoring tool.
Alchemy Eye based products include an HTTP server, which is started by default. However, the web server does not set a password by default. This makes it possible for any user to connect to the web server and view log files. These log files may contain sensitive information about network structure, or other hosts on the network.
This problem makes it possible for a remote user to launch an information gathering attack, and could lead to organized attack against network resources.
Alchemy is a Eye and Alchemy Network Monitor are both products based off the Alchemy Eye network management and server monitoring tool.
Alchemy Eye based products include an HTTP server, which is started by default. However, the web server does not set a password by default. This makes it possible for any user to connect to the web server and view log files. These log files may contain sensitive information about network structure, or other hosts on the network.
This problem makes it possible for a remote user to launch an information gathering attack, and could lead to organized attack against network resources.
Exploit / POC
Alchemy Remote Network Log Viewing Vulnerability
No exploit is required for this vulnerability.
No exploit is required for this vulnerability.
References
Alchemy Remote Network Log Viewing Vulnerability
References:
References: