SurfControl SuperScout WebFilter User Accounts Information Disclosure Vulnerability
BID:5856
Info
SurfControl SuperScout WebFilter User Accounts Information Disclosure Vulnerability
| Bugtraq ID: | 5856 |
| Class: | Access Validation Error |
| CVE: |
CVE-2002-0705 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 02 2002 12:00AM |
| Updated: | Jul 11 2009 05:06PM |
| Credit: | Vulnerability discovery credited to Matt Moore <[email protected]>. |
| Vulnerable: |
SurfControl Web Filter for Windows NT/2000 4.1 SurfControl Web Filter for Windows NT/2000 4.0 SurfControl SuperScout Web Filter for Windows NT/2000 3.0.3 SurfControl SuperScout Web Filter for Windows NT/2000 3.0 |
| Not Vulnerable: | |
Discussion
SurfControl SuperScout WebFilter User Accounts Information Disclosure Vulnerability
SurfControl SuperScout WebFilter is web filtering software for Microsoft Windows operating systems. SurfControl SuperScout WebFilter includes a remotely accessible reporting service.
It has been reported that SuperScout WebFilter insecurely stores some types of information. The reports server included as part of the SuperScout WebFilter package stores sensitive information in a publicly accessible, unrestricted directory. A remote user could gain access to user credentials.
SurfControl SuperScout WebFilter is web filtering software for Microsoft Windows operating systems. SurfControl SuperScout WebFilter includes a remotely accessible reporting service.
It has been reported that SuperScout WebFilter insecurely stores some types of information. The reports server included as part of the SuperScout WebFilter package stores sensitive information in a publicly accessible, unrestricted directory. A remote user could gain access to user credentials.
Solution / Fix
SurfControl SuperScout WebFilter User Accounts Information Disclosure Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.