Mediahouse Statistics Server Cleartext Password Vulnerability
BID:735
Info
Mediahouse Statistics Server Cleartext Password Vulnerability
| Bugtraq ID: | 735 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | Yes |
| Published: | Sep 30 1999 12:00AM |
| Updated: | Sep 30 1999 12:00AM |
| Credit: | Posted to Bugtraq on September 30 by Per Bergehed. |
| Vulnerable: |
MediaHouse Software Statistics Server 5.1 MediaHouse Software Statistics Server 4.28 |
| Not Vulnerable: | |
Discussion
Mediahouse Statistics Server Cleartext Password Vulnerability
The administrative password for MediaHouse's Statistics Server is stored in plaintext in the file ss.cfg . Anyone with read access to this file can gain full control over the Statistics Server.
The administrative password for MediaHouse's Statistics Server is stored in plaintext in the file ss.cfg . Anyone with read access to this file can gain full control over the Statistics Server.
Exploit / POC
Mediahouse Statistics Server Cleartext Password Vulnerability
See discussion.
See discussion.
Solution / Fix
Mediahouse Statistics Server Cleartext Password Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution:
Currently the SecurityFocus staff are not aware of any vendor supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
References
Mediahouse Statistics Server Cleartext Password Vulnerability
References:
References:
- Security flaw in Mediahouse Statistics Server 4.28 & 5.0 (Per Bergehed)
- Statistics Server by MediaHouse Software Inc. (MediaHouse Software Inc.)