Unspecified vulnerability in db.php in NooMS 1.1 allows remote attackers to conduct brute force attacks against passwords via a username in the g_dbuser parameter and a password in the g_dbpwd parameter, and possibly a "localhost" g_dbhost parameter value, related to a "Mysql Remote Brute Force Vulnerability."
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://securityreason.com/securityalert/4289 | third party advisory |
http://www.securityfocus.com/archive/1/496236/100/0/threaded | mailing list |
https://exchange.xforce.ibmcloud.com/vulnerabilities/45076 | vdb entry |