AuditWizard 6.3.2, when using "Remote Audit," logs the administrator password in plaintext to LaytonCmdSvc.log, which allows local users to obtain sensitive information by reading the file.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/28743 | vdb entry |
http://www.securityfocus.com/archive/1/445220/100/0/threaded | mailing list |
http://secunia.com/advisories/21773 | third party advisory vendor advisory |
http://www.vupen.com/english/advisories/2006/3498 | vdb entry |
http://securityreason.com/securityalert/1525 | third party advisory |
http://securitytracker.com/id?1016795 | vdb entry exploit |
http://www.securityfocus.com/bid/19860 | vdb entry |