MDG Web Server 4D Insecure Credential Storage Vulnerability
BID:5803
Info
MDG Web Server 4D Insecure Credential Storage Vulnerability
| Bugtraq ID: | 5803 |
| Class: | Design Error |
| CVE: |
CVE-2002-1521 |
| Remote: | No |
| Local: | Yes |
| Published: | Sep 25 2002 12:00AM |
| Updated: | Jul 11 2009 05:06PM |
| Credit: | Discovery of this issue is credited to Tamer Sahin <[email protected]>. |
| Vulnerable: |
MDG Computer Services Web Server 4D 3.6 |
| Not Vulnerable: | |
Discussion
MDG Web Server 4D Insecure Credential Storage Vulnerability
MDG Web Server 4D is reported to store various types of credentials for optional modules in plaintext on the local filesystem. Local attackers who can read the file containing the credentials may then use the credentials to gain access to other types of sensitive information or perform unauthorized actions.
This issue has been reported in Web Server 4D 3.6. Other versions may also be affected.
MDG Web Server 4D is reported to store various types of credentials for optional modules in plaintext on the local filesystem. Local attackers who can read the file containing the credentials may then use the credentials to gain access to other types of sensitive information or perform unauthorized actions.
This issue has been reported in Web Server 4D 3.6. Other versions may also be affected.
Exploit / POC
MDG Web Server 4D Insecure Credential Storage Vulnerability
There is no exploit code required.
There is no exploit code required.
Solution / Fix
MDG Web Server 4D Insecure Credential Storage Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
MDG Web Server 4D Insecure Credential Storage Vulnerability
References:
References:
- Security Office Advisories (Security Office)