The Ubercart module 6.x-2.x before 6.x-2.8 and 7.x-3.x before 7.x-3.1 for Drupal stores passwords for new customers in plaintext during checkout, which allows local users to obtain sensitive information by reading from the database.
Weaknesses in this category are related to the management of credentials.
Link | Tags |
---|---|
http://www.openwall.com/lists/oss-security/2012/05/03/2 | mailing list |
http://secunia.com/advisories/48935 | third party advisory vendor advisory |
http://drupal.org/node/1547674 | patch vendor advisory |
http://drupal.org/node/1547508 | patch |
http://drupalcode.org/project/ubercart.git/commitdiff/035d2cb | patch exploit |
http://drupalcode.org/project/ubercart.git/commitdiff/8c61e84 | patch exploit |
http://www.openwall.com/lists/oss-security/2012/05/03/1 | mailing list |
http://www.securityfocus.com/bid/53251 | vdb entry |
http://drupal.org/node/1547506 | patch |