PT-2004-2457 · Activepost · Activepost Standard
Luigi Auriemma
·
Publicado
2004-12-31
·
Atualizado
2017-07-11
·
CVE-2004-1549
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
ActivePost Standard version 3.1
Description
The issue allows remote attackers to gain sensitive information by sniffing the network connection, as the conference menu in ActivePost Standard sends passwords of password-protected rooms in cleartext.
Recommendations
For ActivePost Standard version 3.1, consider restricting access to password-protected rooms until a fix is available, and avoid using the conference menu feature to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Activepost Standard