Tridion R5 Plaintext Passwords Information Disclosure Vulnerability
BID:7429
Info
Tridion R5 Plaintext Passwords Information Disclosure Vulnerability
| Bugtraq ID: | 7429 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Apr 24 2003 12:00AM |
| Updated: | Apr 24 2003 12:00AM |
| Credit: | Discovery of this vulnerability has been credited to Dev OXide <[email protected]>. |
| Vulnerable: |
Tridion Tridion R5 SP2 |
| Not Vulnerable: | |
Discussion
Tridion R5 Plaintext Passwords Information Disclosure Vulnerability
Tridion R5 has been reported prone to an information disclosure vulnerability.
It has been reported that Tridion R5 may store sensitive information embedded in certain XML configuration files that are stored on the system. If an attacker has local access and sufficient privileges to view the XML files, plaintext administration credentials may be revealed.
It should be noted that although this vulnerability was reported to affect Tridion R5 SP2 previous versions might also be affected.
Tridion R5 has been reported prone to an information disclosure vulnerability.
It has been reported that Tridion R5 may store sensitive information embedded in certain XML configuration files that are stored on the system. If an attacker has local access and sufficient privileges to view the XML files, plaintext administration credentials may be revealed.
It should be noted that although this vulnerability was reported to affect Tridion R5 SP2 previous versions might also be affected.
Exploit / POC
Tridion R5 Plaintext Passwords Information Disclosure Vulnerability
There is no exploit required.
There is no exploit required.
Solution / Fix
Tridion R5 Plaintext Passwords Information Disclosure Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Tridion R5 Plaintext Passwords Information Disclosure Vulnerability
References:
References:
- Tridion R5 Homepage (Tridion)