Frederic Tyndiuk Eupload Plain Text Password Storage Vulnerability
BID:5369
Info
Frederic Tyndiuk Eupload Plain Text Password Storage Vulnerability
| Bugtraq ID: | 5369 |
| Class: | Design Error |
| CVE: |
CVE-2002-1449 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 31 2002 12:00AM |
| Updated: | Jul 11 2009 02:56PM |
| Credit: | Discovery credited to "\[Zero_Byte\]" <[email protected]>. |
| Vulnerable: |
Frederic Tyndiuk Eupload 1.0 |
| Not Vulnerable: | |
Discussion
Frederic Tyndiuk Eupload Plain Text Password Storage Vulnerability
A problem with Eupload may make it possible for remote attackers to gain access to sensitive information.
Eupload does not cryptographically protect stored passwords. Passwords contained in the configuration file, password.txt, are stored in plain text. They may be read by simply viewing the file. The file, password.txt, is stored in a web accessible location and is, itself, accessible for retrieval. Thus it is trivial for an attacker to obtain user passwords and abuse the Eupload service.
A problem with Eupload may make it possible for remote attackers to gain access to sensitive information.
Eupload does not cryptographically protect stored passwords. Passwords contained in the configuration file, password.txt, are stored in plain text. They may be read by simply viewing the file. The file, password.txt, is stored in a web accessible location and is, itself, accessible for retrieval. Thus it is trivial for an attacker to obtain user passwords and abuse the Eupload service.
Exploit / POC
Frederic Tyndiuk Eupload Plain Text Password Storage Vulnerability
There is no exploit code required.
There is no exploit code required.
Solution / Fix
Frederic Tyndiuk Eupload Plain Text Password Storage Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.