PT-2018-1150 · Docutrac · Office Therapy+1
Publicado
2018-02-09
·
Atualizado
2019-10-09
·
CVE-2018-5551
CVSS v3.1
10
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
DocuTrac QuicDoc and Office Therapy versions with DTISQLInstaller.exe version 1.6.4.0 and prior
Description
The issue is related to the use of predefined credentials in the DTISQLInstaller.exe executable file. This allows a remote attacker to gain access to the software using the QDMaster, OTMaster, and sa accounts.
Recommendations
For versions with DTISQLInstaller.exe version 1.6.4.0 and prior, consider changing the predefined credentials QDMaster, OTMaster, and sa to secure passwords to prevent unauthorized access.
As a temporary workaround, restrict access to the DTISQLInstaller.exe executable file until a secure version is available.
Exploit
Correção
Using Hardcoded Credentials
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Docutrac Quicdoc
Office Therapy