OSVDB ID: 9925

Title: Regulus stafffile Password File Disclosure

Info

Disclosure

Sep 07, 2004

Discovery

Unknown

Dates

Exploit

Sep 07, 2004

Solution

Unknown

Description

Regulus contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when an attacker submits a specially crafted URL, which will disclose the users and the encrypted passwords resulting in a loss of confidentiality.

Classification

Location: Remote/Network Access Required
Attack Type: Information Disclosure, Misconfiguration
Impact: Loss of Confidentiality
Exploit: Exploit Available
Disclosure: OSVDB Verified
OSVDB: Web Related

Solution

Currently, there are no known upgrades, patches, or workarounds available to correct this issue.

Products

S.A.F.E. Inc.

Regulus

2.2-95

References

Credit

  • - masud_libraBrand New Doo Doohotmail.com -


Direct URL: http://osvdb.org/36218