Invision Board限制论坛明文密码漏洞

Invision Board限制论坛明文密码漏洞

漏洞ID 1202170 漏洞类型 设计错误
发布时间 2003-12-31 更新时间 2003-12-31
图片[1]-Invision Board限制论坛明文密码漏洞-安全小百科CVE编号 CVE-2003-1454
图片[2]-Invision Board限制论坛明文密码漏洞-安全小百科CNNVD-ID CNNVD-200312-254
漏洞平台 N/A CVSS评分 5.0
|漏洞来源
https://cxsecurity.com/issue/WLB-2007100097
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200312-254
|漏洞详情
InvisionPowerServicesInvisionBoard1.0至1.1.1版本存在漏洞,当一个论坛的密码被保护时,该软件在cookie中以明文的方式存储该管理员密码,远程攻击者利用该漏洞获取访问权限。
|漏洞EXP


Invision Power Board Plaintext Password Disclosure Vuln

-------------------------------------------------------

Version: All?

Problem: Invision Power Board gives an admin the option

to create a pass protected forum. The problem with this

is that the password is then stored in the cookie fully

readable as it is shown in plaintext.

Credits: All credit goes to JeiAr of GulfTech Computers
|参考资料

来源:XF
名称:invision-admin-plaintext-password(11871)
链接:http://xforce.iss.net/xforce/xfdb/11871
来源:BID
名称:7440
链接:http://www.securityfocus.com/bid/7440
来源:BUGTRAQ
名称:20030425InvisionPowerBoardPlaintextPasswordDisclosureVuln
链接:http://www.securityfocus.com/archive/1/319747
来源:SREASON
名称:3276
链接:http://securityreason.com/securityalert/3276

相关推荐: ListMail 112 – Command Execution

ListMail 112 – Command Execution 漏洞ID 1053479 漏洞类型 发布时间 2000-11-17 更新时间 2000-11-17 CVE编号 N/A CNNVD-ID N/A 漏洞平台 CGI CVSS评分 N/A |漏洞来…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享