The notifyendsubs cron job in Campsite before 2.3.3 sends an e-mail message containing a certain unencrypted MySQL password, which allows remote attackers to sniff the password.
Link | Tags |
---|---|
http://sourceforge.net/project/shownotes.php?release_id=367403&group_id=66936 | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/23106 | vdb entry |
http://www.osvdb.org/20698 | patch vdb entry |
http://secunia.com/advisories/17528 | patch vendor advisory third party advisory |