PT-2005-4210 · Eyeos · Eyeos
Publicado
2005-11-01
·
Atualizado
2017-07-11
·
CVE-2005-3414
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
eyeOS version 0.8.4
Description
The issue allows remote attackers to obtain user credentials due to insufficient access control of the usrinfo.xml file, which is stored under the web document root.
Recommendations
For eyeOS version 0.8.4, consider restricting access to the usrinfo.xml file to prevent remote attackers from obtaining user credentials. As a temporary workaround, restrict access to the web document root until a proper fix is applied.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Eyeos