ContentKeeper 123.25 and earlier places passwords in cleartext in an INPUT element in cgi-bin/ck/changepw.cgi, which allows remote authenticated users to obtain passwords via this URI.
References
Configurations
History
No history.
Information
Published : 2006-09-27 23:07
Updated : 2024-02-28 11:01
NVD link : CVE-2006-5018
Mitre link : CVE-2006-5018
CVE.ORG link : CVE-2006-5018
JSON object : View
Products Affected
contentkeeper_technologies
- contentkeeper
CWE