PT-2011-1058 · Debian · Domain Technologie Control

Publicado

2011-03-07

·

Atualizado

2017-08-17

·

CVE-2011-0436

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Domain Technologie Control (DTC) versions prior to 0.32.9
Description The issue concerns multiple vulnerabilities in the DTC package of the Debian GNU/Linux operating system, which can be exploited remotely to compromise the confidentiality, integrity, and availability of protected information. Specifically, the register user function in client/new account form.php includes a cleartext password in an email message, making it easier for remote attackers to obtain sensitive information by sniffing the network.
Recommendations For versions prior to 0.32.9, update to version 0.32.9 or later to resolve the issue. As a temporary workaround, consider disabling the register user function in client/new account form.php to minimize the risk of exploitation. Restrict access to the client/new account form.php file to prevent unauthorized access.

Correção

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-03561
CVE-2011-0436
DSA-2179-1

Produtos afetados

Domain Technologie Control