Webgate WebEye Information Disclosure Vulnerability
BID:9169
Info
Webgate WebEye Information Disclosure Vulnerability
| Bugtraq ID: | 9169 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 08 2003 12:00AM |
| Updated: | Dec 08 2003 12:00AM |
| Credit: | The disclosure of this issue has been credited to datapath <[email protected]>. |
| Vulnerable: |
Webgate WebEye SPD Webgate WebEye E20 Webgate WebEye E104 Webgate WebEye E10 Webgate WebEye B106 Webgate WebEye B101 |
| Not Vulnerable: | |
Discussion
Webgate WebEye Information Disclosure Vulnerability
It has been reported that WebEye is prone to an information disclosure vulnerability that may allow an attacker to harvest sensitive information from the server such as usernames and passwords. The problem exists in the '/admin/wg_user-info.ml' script that fails to verify user credentials before returning sensitive information.
It has been reported that WebEye is prone to an information disclosure vulnerability that may allow an attacker to harvest sensitive information from the server such as usernames and passwords. The problem exists in the '/admin/wg_user-info.ml' script that fails to verify user credentials before returning sensitive information.
Exploit / POC
Webgate WebEye Information Disclosure Vulnerability
The following exploit code has been released:
The following exploit code has been released:
Solution / Fix
Webgate WebEye Information Disclosure Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.