PT-2008-5479 · Nooms · Nooms

Dr.Crash

+1

·

Publicado

2008-09-23

·

Atualizado

2018-10-11

·

CVE-2008-4180

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions NooMS version 1.1
Description The issue allows remote attackers to conduct brute force attacks against passwords. This is achieved by providing a username in the g dbuser parameter and a password in the g dbpwd parameter. The attack might also involve setting the g dbhost parameter to a "localhost" value.
Recommendations For NooMS version 1.1, consider restricting access to the db.php file to prevent brute force attacks, and limit the number of login attempts to mitigate the risk of exploitation. As a temporary workaround, restrict the use of the g dbuser and g dbpwd parameters until a patch is available.

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-4180

Produtos afetados

Nooms