Gabber 0.8.7 sends an email to a specific address during user login and logout, which allows remote attackers to obtain user session activity and Gabber version number by sniffing.
Weaknesses in this category are typically introduced during the configuration of the software.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/6624 | vdb entry |
http://archives.neohapsis.com/archives/bugtraq/2003-01/0179.html | mailing list |
https://exchange.xforce.ibmcloud.com/vulnerabilities/11115 | vdb entry |