H-Sphere Winbox 2.4.2 and 2.4.3 RC1 stores sensitive information such as username and password in plaintext in world-readable log files, which allows local users to gain privileges.
References
Configurations
Configuration 1 (hide)
|
History
20 Nov 2024, 23:57
Type | Values Removed | Values Added |
---|---|---|
References | () http://exploitlabs.com/files/advisories/EXPL-A-2005-007-hsphere.txt - Exploit, Patch | |
References | () http://secunia.com/advisories/15287 - Patch | |
References | () http://www.osvdb.org/16239 - | |
References | () http://www.psoft.net/misc/hsphere_winbox_security_update_passwd.html - Patch | |
References | () http://www.securityfocus.com/bid/13559 - Exploit, Patch | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/20522 - |
Information
Published : 2005-05-16 04:00
Updated : 2024-11-20 23:57
NVD link : CVE-2005-1606
Mitre link : CVE-2005-1606
CVE.ORG link : CVE-2005-1606
JSON object : View
Products Affected
positive_software
- h-sphere_winbox
CWE