PT-2004-2167 · Pafiledb · Pafiledb
Publicado
2004-12-15
·
Atualizado
2017-07-11
·
CVE-2004-1219
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
paFileDB version 3.1
Description:
The issue allows remote attackers to read the administrator's password hash and conduct brute force password guessing attacks by listing the contents of the sessions directory and reading the associated file for the administrator session, when sessions authentication is used and the administrator logs on.
Recommendations:
For paFileDB version 3.1, consider restricting access to the sessions directory to prevent unauthorized reading of the administrator's session file as a temporary workaround.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Pafiledb