Programi Bilanc Build 007 Release 014 31.01.2020 supplies a .exe file containing several hardcoded credentials to different servers that allow remote attackers to gain access to the complete infrastructure including the website, update server, and external issue tracking tools.
The product contains hard-coded credentials, such as a password or cryptographic key.
Link | Tags |
---|---|
http://seclists.org/fulldisclosure/2020/Dec/38 | third party advisory mailing list |
https://packetstormsecurity.com/files/160626/Programi-Bilanc-Build-007-Release-014-31.01.2020-Hardcoded-Credentials.html | third party advisory vdb entry |