Ingenium Learning Management System Information Disclosure Vulnerability
BID:5969
Info
Ingenium Learning Management System Information Disclosure Vulnerability
| Bugtraq ID: | 5969 |
| Class: | Configuration Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 15 2002 12:00AM |
| Updated: | Oct 15 2002 12:00AM |
| Credit: | Discovery of this issue is credited to Brian Enigma <[email protected]>. |
| Vulnerable: |
Click2Learn Ingenium Learning Management System 6.1 Click2Learn Ingenium Learning Management System 5.1 |
| Not Vulnerable: | |
Discussion
Ingenium Learning Management System Information Disclosure Vulnerability
The default installation of Ingenium Learning Management System leaves sensitive configuration information in a directory which is publicly accessible via the web. This may lead to disclosure of the hash for the administrative password, database authentication credentials and other sensitive information.
The default installation of Ingenium Learning Management System leaves sensitive configuration information in a directory which is publicly accessible via the web. This may lead to disclosure of the hash for the administrative password, database authentication credentials and other sensitive information.
Solution / Fix
Ingenium Learning Management System Information Disclosure Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.