DBTools DBManager Professional Information Disclosure Weakness
BID:7040
Info
DBTools DBManager Professional Information Disclosure Weakness
| Bugtraq ID: | 7040 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Mar 07 2003 12:00AM |
| Updated: | Mar 07 2003 12:00AM |
| Credit: | Discovery of this issue is credited to Ignacio Vazquez <[email protected]>. |
| Vulnerable: |
DBTools DBManager Professional 2.0.1 |
| Not Vulnerable: | |
Discussion
DBTools DBManager Professional Information Disclosure Weakness
Sensitive DBManager Professional configuration information, including authentication credentials, is stored in plaintext on the system hosting the software. This information may also be readable by other local users in the default installation of the software.
Sensitive DBManager Professional configuration information, including authentication credentials, is stored in plaintext on the system hosting the software. This information may also be readable by other local users in the default installation of the software.
Exploit / POC
DBTools DBManager Professional Information Disclosure Weakness
There is no exploit required.
There is no exploit required.
Solution / Fix
DBTools DBManager Professional Information Disclosure Weakness
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
DBTools DBManager Professional Information Disclosure Weakness
References:
References:
- DBManager Professional Product Page (DBTools)
- DBTools' DBManager Information Leak Vulnerability (Ignacio Vazquez
)