H-Sphere Winbox 2.4.2 and 2.4.3 RC1 stores sensitive information such as username and password in plaintext in world-readable log files, which allows local users to gain privileges.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/13559 | exploit vdb entry patch |
http://www.osvdb.org/16239 | vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/20522 | vdb entry |
http://secunia.com/advisories/15287 | third party advisory patch |
http://exploitlabs.com/files/advisories/EXPL-A-2005-007-hsphere.txt | patch exploit |
http://www.psoft.net/misc/hsphere_winbox_security_update_passwd.html | patch |