PT-2005-4210 · Eyeos · Eyeos

Published

2005-11-01

·

Updated

2017-07-11

·

CVE-2005-3414

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions eyeOS version 0.8.4
Description The issue allows remote attackers to obtain user credentials due to insufficient access control of the usrinfo.xml file, which is stored under the web document root.
Recommendations For eyeOS version 0.8.4, consider restricting access to the usrinfo.xml file to prevent remote attackers from obtaining user credentials. As a temporary workaround, restrict access to the web document root until a proper fix is applied.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-3414

Affected Products

Eyeos