Invision Board Restricted Forum Plaintext Password Vulnerability
BID:7440
Info
Invision Board Restricted Forum Plaintext Password Vulnerability
| Bugtraq ID: | 7440 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Apr 25 2003 12:00AM |
| Updated: | Apr 25 2003 12:00AM |
| Credit: | Discovery of this vulnerability has been credited to JeiAr <[email protected]>. |
| Vulnerable: |
Invision Power Services Invision Board 1.1.1 Invision Power Services Invision Board 1.0.1 Invision Power Services Invision Board 1.0 |
| Not Vulnerable: | |
Discussion
Invision Board Restricted Forum Plaintext Password Vulnerability
Invision Board has been reported to store restricted forum credentials as plain text embedded in cookie data.
If the Invision Board admin 'pass protected' option is activated for a specific forum, on attempted access to the controlled area, the restricted forum password is reportedly stored as plaintext in a local cookie.
It should be noted that although unconfirmed this vulnerability was reported to affect all versions of Invision Power Board.
Invision Board has been reported to store restricted forum credentials as plain text embedded in cookie data.
If the Invision Board admin 'pass protected' option is activated for a specific forum, on attempted access to the controlled area, the restricted forum password is reportedly stored as plaintext in a local cookie.
It should be noted that although unconfirmed this vulnerability was reported to affect all versions of Invision Power Board.
Exploit / POC
Invision Board Restricted Forum Plaintext Password Vulnerability
There is no exploit required.
There is no exploit required.
Solution / Fix
Invision Board Restricted Forum Plaintext Password Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Invision Board Restricted Forum Plaintext Password Vulnerability
References:
References: