PT-2006-1963 · Oi! · Oi! Email Marketing System

H4Cky0U

+1

·

Publicado

2006-02-28

·

Atualizado

2018-10-18

·

CVE-2006-0920

CVSS v2.0

1.7

Baixa

VetorAV:L/AC:L/Au:S/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Oi! Email Marketing System version 3.0
Description The issue allows local users with superadministrator privileges, or attackers who have obtained access to the web page, to view the server's FTP password stored in cleartext on a Configuration web page.
Recommendations For Oi! Email Marketing System version 3.0, consider restricting access to the Configuration web page to minimize the risk of exploitation. As a temporary workaround, limit the privileges of local users to prevent them from accessing sensitive configuration details. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-0920

Produtos afetados

Oi! Email Marketing System