Fastlink Software TheServer Plain Text Password Storage Vulnerability
BID:5250
Info
Fastlink Software TheServer Plain Text Password Storage Vulnerability
| Bugtraq ID: | 5250 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 17 2002 12:00AM |
| Updated: | Jul 17 2002 12:00AM |
| Credit: | Discovery credited to "Larry W. Cashdollar" <[email protected]>. |
| Vulnerable: |
Fastlink Software TheServer 1.75 |
| Not Vulnerable: | |
Discussion
Fastlink Software TheServer Plain Text Password Storage Vulnerability
A problem with TheServer may make it possible for remote attackers to gain access to sensitive information.
TheServer does not cryptographically protect stored passwords. Passwords contained in the configuration file are stored in plain text. They may be read by simply viewing the file. The file (server.ini) is stored in a web accessible location and is, itself, accessible for retrieval by remote attackers using a web browser.
A problem with TheServer may make it possible for remote attackers to gain access to sensitive information.
TheServer does not cryptographically protect stored passwords. Passwords contained in the configuration file are stored in plain text. They may be read by simply viewing the file. The file (server.ini) is stored in a web accessible location and is, itself, accessible for retrieval by remote attackers using a web browser.
Exploit / POC
Fastlink Software TheServer Plain Text Password Storage Vulnerability
There is no exploit code required.
There is no exploit code required.