PT-2005-4210 · Eyeos · Eyeos
Published
2005-11-01
·
Updated
2017-07-11
·
CVE-2005-3414
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
eyeOS version 0.8.4
Description
The issue allows remote attackers to obtain user credentials due to insufficient access control of the usrinfo.xml file, which is stored under the web document root.
Recommendations
For eyeOS version 0.8.4, consider restricting access to the usrinfo.xml file to prevent remote attackers from obtaining user credentials. As a temporary workaround, restrict access to the web document root until a proper fix is applied.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Eyeos