ibillpm.pl in iBill password management system generates weak passwords based on a client's MASTER_ACCOUNT, which allows remote attackers to modify account information in the .htpasswd file via brute force password guessing.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/3476 | vdb entry exploit |
https://exchange.xforce.ibmcloud.com/vulnerabilities/7352 | vdb entry |
http://marc.info/?l=bugtraq&m=100404371423927&w=2 | mailing list |