Infobot Default User Account And Password Vulnerability
BID:7970
Info
Infobot Default User Account And Password Vulnerability
| Bugtraq ID: | 7970 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 18 2003 12:00AM |
| Updated: | Jun 18 2003 12:00AM |
| Credit: | Discovery of this vulnerability has been credited to "morning_wood" <[email protected]>. |
| Vulnerable: |
Infobot Infobot 0.45.3 |
| Not Vulnerable: | |
Discussion
Infobot Default User Account And Password Vulnerability
Infobot has been reported prone to a default password vulnerability. Reportedly Infobot is shipped with two user accounts active by default. A remote attacker may be able to use these account credentials to compromise the host that is running Infobot.
Although this vulnerability has been reported to affect Infobot version 0.45.3, other versions may also be affected.
Infobot has been reported prone to a default password vulnerability. Reportedly Infobot is shipped with two user accounts active by default. A remote attacker may be able to use these account credentials to compromise the host that is running Infobot.
Although this vulnerability has been reported to affect Infobot version 0.45.3, other versions may also be affected.
Exploit / POC
Infobot Default User Account And Password Vulnerability
There is no exploit required.
There is no exploit required.
Solution / Fix
Infobot Default User Account And Password Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.