Lxlabs Kloxo Hosting Platform and HyperVM Local Information Disclosure Vulnerability
BID:36142
Info
Lxlabs Kloxo Hosting Platform and HyperVM Local Information Disclosure Vulnerability
| Bugtraq ID: | 36142 |
| Class: | Unknown |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Aug 25 2009 12:00AM |
| Updated: | Aug 25 2009 08:12PM |
| Credit: | Xia Shing Zee |
| Vulnerable: |
Lxlabs Kloxo Hosting Platform 5.75 Lxlabs HyperVM 2.0.972 Lxlabs HyperVM 2.0 |
| Not Vulnerable: | |
Discussion
Lxlabs Kloxo Hosting Platform and HyperVM Local Information Disclosure Vulnerability
Lxlabs Kloxo Hosting Platform and HyperVM are prone to a local information-disclosure vulnerability because it fails to adequately protect authentication credentials.
Local attackers can exploit this issue to obtain superuser authentication credentials. Successful attacks will lead to a complete compromise of affected computers.
Kloxo Hosting Platform 5.75 is vulnerable; other versions may also be affected. This issue also affects unknown versions of HyperVM.
Lxlabs Kloxo Hosting Platform and HyperVM are prone to a local information-disclosure vulnerability because it fails to adequately protect authentication credentials.
Local attackers can exploit this issue to obtain superuser authentication credentials. Successful attacks will lead to a complete compromise of affected computers.
Kloxo Hosting Platform 5.75 is vulnerable; other versions may also be affected. This issue also affects unknown versions of HyperVM.
Exploit / POC
Lxlabs Kloxo Hosting Platform and HyperVM Local Information Disclosure Vulnerability
To exploit this issue, an attacker requires local interactive access to an affected computer.
To exploit this issue, an attacker requires local interactive access to an affected computer.
Solution / Fix
Lxlabs Kloxo Hosting Platform and HyperVM Local Information Disclosure Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Lxlabs Kloxo Hosting Platform and HyperVM Local Information Disclosure Vulnerability
References:
References: