Click2Learn Ingenium Learning Management System 5.1 and 6.1 stores the hashed administrative password in a config.txt file under the htdocs directory, which allows remote attackers to obtain the administrative password.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/5969 | vdb entry |
http://www.iss.net/security_center/static/10387.php | vdb entry |
http://online.securityfocus.com/archive/1/295309 | mailing list |