BaSoMail Server Plaintext Password Vulnerability
BID:7722
Info
BaSoMail Server Plaintext Password Vulnerability
| Bugtraq ID: | 7722 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | May 28 2003 12:00AM |
| Updated: | May 28 2003 12:00AM |
| Credit: | Discovery of this vulnerability has been credited to Ziv Kamir <[email protected]>. |
| Vulnerable: |
Baardsen Software BaSoMail 1.24 |
| Not Vulnerable: | |
Discussion
BaSoMail Server Plaintext Password Vulnerability
A problem with the BaSoMail Server could make unauthorized access to credentials possible.
It has been reported that a problem exists due to the storage of passwords in plain text format. This could lead to local users gaining unauthorized access to passwords, and potentially unauthorized access to the BaSoMail Server.
A problem with the BaSoMail Server could make unauthorized access to credentials possible.
It has been reported that a problem exists due to the storage of passwords in plain text format. This could lead to local users gaining unauthorized access to passwords, and potentially unauthorized access to the BaSoMail Server.
Exploit / POC
BaSoMail Server Plaintext Password Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
BaSoMail Server Plaintext Password Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.