Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Illuminatus

Researcher fromh4cky0u Security Forums
#53595of 53,635
1.7Total CVSS
Vulnerabilities · 1
PT-2006-1963
1.7
2006-02-28
Oi! · Oi! Email Marketing System · CVE-2006-0920
**Name of the Vulnerable Software and Affected Versions** Oi! Email Marketing System version 3.0 **Description** The issue allows local users with superadministrator privileges, or attackers who have obtained access to the web page, to view the server's FTP password stored in cleartext on a Configuration web page. **Recommendations** For Oi! Email Marketing System version 3.0, consider restricting access to the Configuration web page to minimize the risk of exploitation. As a temporary workaround, limit the privileges of local users to prevent them from accessing sensitive configuration details. At the moment, there is no information about a newer version that contains a fix for this vulnerability.