Abyss Web Server Plaintext Administrative Password Vulnerability
BID:4467
Info
Abyss Web Server Plaintext Administrative Password Vulnerability
| Bugtraq ID: | 4467 |
| Class: | Design Error |
| CVE: |
CVE-2002-0544 |
| Remote: | No |
| Local: | Yes |
| Published: | Apr 07 2002 12:00AM |
| Updated: | Jul 11 2009 11:56AM |
| Credit: | Discovery of this issue is credited to "Jeremy Roberts" <[email protected]>. |
| Vulnerable: |
Aprelium Technologies Abyss Web Server 1.0 |
| Not Vulnerable: | |
Discussion
Abyss Web Server Plaintext Administrative Password Vulnerability
Abyss Web Server is a freely available personal web server. It is maintained by Aprelium Technologies and runs on Microsoft Windows operating systems, as well as Linux.
The administrative password for Abyss Web Server is stored in plaintext in the configuration file. If a local attacker can read the configuration file, they can trivially gain administrative access to the web server.
Additionally, BugTraq ID 4466 "Abyss Web Server File Disclosure Vulnerability" describes an issue which may also enable remote attackers to trivially disclose the contents of the Abyss Web Server configuration file.
This issue was reported for Abyss Web Server for Microsoft Windows operating systems. It is not known whether the Linux version is also affected by this vulnerability.
Abyss Web Server is a freely available personal web server. It is maintained by Aprelium Technologies and runs on Microsoft Windows operating systems, as well as Linux.
The administrative password for Abyss Web Server is stored in plaintext in the configuration file. If a local attacker can read the configuration file, they can trivially gain administrative access to the web server.
Additionally, BugTraq ID 4466 "Abyss Web Server File Disclosure Vulnerability" describes an issue which may also enable remote attackers to trivially disclose the contents of the Abyss Web Server configuration file.
This issue was reported for Abyss Web Server for Microsoft Windows operating systems. It is not known whether the Linux version is also affected by this vulnerability.
Exploit / POC
Abyss Web Server Plaintext Administrative Password Vulnerability
There is no exploit code required.
There is no exploit code required.
Solution / Fix
Abyss Web Server Plaintext Administrative Password Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Abyss Web Server Plaintext Administrative Password Vulnerability
References:
References:
- Abyss Web Server Homepage (Aprelium Technologies)