Trustwave WebDefend Enterprise Multiple Information Disclosure Vulnerabilities
BID:47829
Info
Trustwave WebDefend Enterprise Multiple Information Disclosure Vulnerabilities
| Bugtraq ID: | 47829 |
| Class: | Design Error |
| CVE: |
CVE-2011-0756 CVE-2011-1906 |
| Remote: | Yes |
| Local: | No |
| Published: | May 12 2011 12:00AM |
| Updated: | May 23 2011 09:51AM |
| Credit: | Nathan Power |
| Vulnerable: |
Trustwave WebDefend Enterprise 5.0 |
| Not Vulnerable: |
Trustwave WebDefend 5.0 7.01.903-1.4 |
Discussion
Trustwave WebDefend Enterprise Multiple Information Disclosure Vulnerabilities
Trustwave WebDefend Enterprise is prone to multiple information-disclosure vulnerabilities.
Remote attackers can exploit these issues to gain access to sensitive information that may aid in further attacks.
Trustwave WebDefend Enterprise is prone to multiple information-disclosure vulnerabilities.
Remote attackers can exploit these issues to gain access to sensitive information that may aid in further attacks.
Exploit / POC
Trustwave WebDefend Enterprise Multiple Information Disclosure Vulnerabilities
An attacker can leverage this issue using readily available network utilities.
An attacker can leverage this issue using readily available network utilities.
Solution / Fix
Trustwave WebDefend Enterprise Multiple Information Disclosure Vulnerabilities
Solution:
Some reports state that the latest version of the application may still be vulnerable. However Symantec has not confirmed it. Please contact the vendor for more information.
Solution:
Some reports state that the latest version of the application may still be vulnerable. However Symantec has not confirmed it. Please contact the vendor for more information.
References
Trustwave WebDefend Enterprise Multiple Information Disclosure Vulnerabilities
References:
References:
- TEKUVA Password Reminder - Fix available (TEKUVA)
- Trustwave WebDefend Static Database Password Vulnerability (Nathan Power)