PT-2004-3291 · Mysql Server+2 · Mysql Server+2

Published

2004-12-31

·

Updated

2017-07-11

·

CVE-2004-2398

CVSS v2.0

2.1

Low

VectorAV:L/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Netenberg Fantastico De Luxe version 2.8
Description: The issue allows local users to determine valid usernames by reading database file names, which can lead to brute force attacks. This is possible because the database file names contain associated usernames and are stored in a directory with world-readable permissions, specifically /var/lib/mysql, which is assigned these permissions by cPanel 9.3.0 R5.
Recommendations: For Netenberg Fantastico De Luxe version 2.8, consider restricting access to the /var/lib/mysql directory to prevent local users from reading database file names and determining valid usernames. As a temporary workaround, restrict the world-readable permissions assigned by cPanel to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2004-2398

Affected Products

Mysql Server
Netenberg Fantastico De Luxe
Cpanel