PT-2004-2167 · Pafiledb · Pafiledb

Publicado

2004-12-15

·

Atualizado

2017-07-11

·

CVE-2004-1219

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions: paFileDB version 3.1
Description: The issue allows remote attackers to read the administrator's password hash and conduct brute force password guessing attacks by listing the contents of the sessions directory and reading the associated file for the administrator session, when sessions authentication is used and the administrator logs on.
Recommendations: For paFileDB version 3.1, consider restricting access to the sessions directory to prevent unauthorized reading of the administrator's session file as a temporary workaround.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2004-1219

Produtos afetados

Pafiledb