Trustwave WebDefend Enterprise before 5.0 7.01.903-1.4 stores specific user-account credentials in a MySQL database, which makes it easier for remote attackers to read the event collection table via requests to the management port, a different vulnerability than CVE-2011-0756.
Weaknesses in this category are related to the management of credentials.
Link | Tags |
---|---|
https://www.trustwave.com/spiderlabs/advisories/TWSL2011-001.txt | vendor advisory |
http://securitytracker.com/id?1025447 | vdb entry |