PT-2006-1963 · Oi! · Oi! Email Marketing System

H4Cky0U

+1

·

Published

2006-02-28

·

Updated

2018-10-18

·

CVE-2006-0920

CVSS v2.0

1.7

Low

VectorAV:L/AC:L/Au:S/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Oi! Email Marketing System version 3.0
Description The issue allows local users with superadministrator privileges, or attackers who have obtained access to the web page, to view the server's FTP password stored in cleartext on a Configuration web page.
Recommendations For Oi! Email Marketing System version 3.0, consider restricting access to the Configuration web page to minimize the risk of exploitation. As a temporary workaround, limit the privileges of local users to prevent them from accessing sensitive configuration details. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-0920

Affected Products

Oi! Email Marketing System