IRCXpro Server Settings.INI Plaintext Password Storage Vulnerability
BID:7792
Info
IRCXpro Server Settings.INI Plaintext Password Storage Vulnerability
| Bugtraq ID: | 7792 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 03 2003 12:00AM |
| Updated: | Jun 03 2003 12:00AM |
| Credit: | Discovery of this vulnerability credited to morning_wood [email protected]. |
| Vulnerable: |
IRCXpro IRCXpro Server 1.0 |
| Not Vulnerable: |
IRCXpro IRCXpro Server 1.1 |
Discussion
IRCXpro Server Settings.INI Plaintext Password Storage Vulnerability
A problem with the IRCXpro Server could make unauthorized access to credentials possible.
It has been reported that a problem exists in the method used for the storage of passwords by IRCXPro. This could lead to local users gaining unauthorized access to passwords, and potentially unauthorized access to the vulnerable IRC server.
A problem with the IRCXpro Server could make unauthorized access to credentials possible.
It has been reported that a problem exists in the method used for the storage of passwords by IRCXPro. This could lead to local users gaining unauthorized access to passwords, and potentially unauthorized access to the vulnerable IRC server.
Exploit / POC
IRCXpro Server Settings.INI Plaintext Password Storage Vulnerability
There is no exploit required.
There is no exploit required.
Solution / Fix
IRCXpro Server Settings.INI Plaintext Password Storage Vulnerability
Solution:
The vendor has released an upgrade to address this issue:
IRCXpro IRCXpro Server 1.0
Solution:
The vendor has released an upgrade to address this issue:
IRCXpro IRCXpro Server 1.0
-
IRCXpro IRCXpro Server 1.1
http://www.ircxpro.com/default.asp?id=download
References
IRCXpro Server Settings.INI Plaintext Password Storage Vulnerability
References:
References:
- IRCXpro (IRCXpro)
- Resolved - IRCX Pro ("morning_wood"
)