OSVDB ID: 10354

Title: Web Wiz Journal journal.mdb Admin Password Disclosure

Info

Disclosure

Sep 27, 2004

Discovery

Unknown

Dates

Exploit

Sep 27, 2004

Solution

Unknown

Description

Web Wiz Journal contains a flaw that may lead to an unauthorized password exposure. It is possible to gain access to plaintext administrator passwords when a remote user downloads the database with a certain type of URL, which may lead to a loss of confidentiality and/or integrity.

Classification

Location: Remote/Network Access Required
Attack Type: Information Disclosure
Impact: Loss of Confidentiality
Exploit: Exploit Available
Disclosure: OSVDB Verified

Solution

Currently, there are no known upgrades, patches, or workarounds available to correct this issue.

Products

Web Wiz

Web Wiz Journal

1.0

References

Credit

Unknown or Incomplete



Direct URL: http://osvdb.org/36218