PT-2008-4296 · Oracle+1 · Mysql Server+1

T0Pp8Uzz

·

Published

2008-06-25

·

Updated

2017-09-29

·

CVE-2008-2857

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions AlstraSoft AskMe Pro versions 2.1 and earlier
Description The issue allows context-dependent attackers to obtain sensitive information because passwords are stored in cleartext in a MySQL database.
Recommendations For AlstraSoft AskMe Pro versions 2.1 and earlier, consider updating the password storage mechanism to hash and salt passwords instead of storing them in cleartext. As a temporary workaround, restrict access to the MySQL database to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-2857

Affected Products

Alstrasoft Askme Pro
Mysql Server