authenticate_ad_setup_finished.cfm in MediaCAST 8 and earlier allows remote attackers to discover usernames and cleartext passwords by reading the error messages returned for requests that use the UserID parameter.
References
Configurations
History
21 Nov 2024, 01:11
Type | Values Removed | Values Added |
---|---|---|
References | () http://secunia.com/advisories/44182 - Vendor Advisory | |
References | () http://securityreason.com/securityalert/8245 - | |
References | () http://www.osvdb.org/72079 - | |
References | () http://www.packetninjas.net/storage/advisories/MediaCast-PWDump-FINAL.txt - Exploit | |
References | () http://www.securityfocus.com/bid/47572 - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/67082 - |
Information
Published : 2011-05-10 19:55
Updated : 2024-11-21 01:11
NVD link : CVE-2010-0216
Mitre link : CVE-2010-0216
CVE.ORG link : CVE-2010-0216
JSON object : View
Products Affected
inventivetec
- mediacast
CWE
CWE-310
Cryptographic Issues