NNT Change Tracker Enterprise Hard Coded Encryption Local Security Bypass Vulnerability
BID:47959
Info
NNT Change Tracker Enterprise Hard Coded Encryption Local Security Bypass Vulnerability
| Bugtraq ID: | 47959 |
| Class: | Unknown |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | May 24 2011 12:00AM |
| Updated: | Jun 29 2011 07:20PM |
| Credit: | Dennis Brunnen |
| Vulnerable: |
NNT Change Tracker 4.7 |
| Not Vulnerable: |
NNT Change Tracker 5 |
Discussion
NNT Change Tracker Enterprise Hard Coded Encryption Local Security Bypass Vulnerability
NNT Change Tracker is prone to a local security-bypass vulnerability.
A local attacker could exploit this issue to modify files without the application detecting the changes and to fabricate changes that have not occurred. This may aid in further attacks.
NNT Change Tracker is prone to a local security-bypass vulnerability.
A local attacker could exploit this issue to modify files without the application detecting the changes and to fabricate changes that have not occurred. This may aid in further attacks.
Exploit / POC
NNT Change Tracker Enterprise Hard Coded Encryption Local Security Bypass Vulnerability
An attacker can use readily available text editing applications to exploit this issue.
An attacker can use readily available text editing applications to exploit this issue.
Solution / Fix
NNT Change Tracker Enterprise Hard Coded Encryption Local Security Bypass Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
NNT Change Tracker Enterprise Hard Coded Encryption Local Security Bypass Vulnerability
References:
References: