QID 730061
Date Published: 2021-04-27
QID 730061: SIPS User Information Disclosure Vulnerability
SIPS is a Web log and link indexing system. It's available for Unix and Linux variants, and Microsoft Windows operating systems.
It has been reported that SIPS fails to authenticate users before granting access to user account information. As a result, it may be possible for an attacker to access sensitive data by making a request to a specific location, including the first letter of a username followed by the full username.
It should be noted that this vulnerability was reported in SIPS Version 0.2.2, however later versions retain the naming scheme and should also be considered vulnerable.
QID Detection Logic:
This QID checks for vulnerable version by sending GET request to d/default/user webpage.
If this vulnerability is successfully exploited, an attacker could gain access to sensitive user account data, which could aid in further attacks.
CVEs related to QID 730061
| Advisory ID | Software | Component | Link |
|---|