PT-2004-3291 · Mysql Server+2 · Mysql Server+2
Published
2004-12-31
·
Updated
2017-07-11
·
CVE-2004-2398
CVSS v2.0
2.1
Low
| Vector | AV:L/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
Netenberg Fantastico De Luxe version 2.8
Description:
The issue allows local users to determine valid usernames by reading database file names, which can lead to brute force attacks. This is possible because the database file names contain associated usernames and are stored in a directory with world-readable permissions, specifically /var/lib/mysql, which is assigned these permissions by cPanel 9.3.0 R5.
Recommendations:
For Netenberg Fantastico De Luxe version 2.8, consider restricting access to the /var/lib/mysql directory to prevent local users from reading database file names and determining valid usernames. As a temporary workaround, restrict the world-readable permissions assigned by cPanel to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mysql Server
Netenberg Fantastico De Luxe
Cpanel