Vulnerabilities > CVE-2002-0324 - Unspecified vulnerability in Noah Gray Graymatter
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Greymatter 1.21c and earlier with the Bookmarklet feature enabled allows remote attackers to read a cleartext password and gain administrative privileges by guessing the name of a gmrightclick-*.reg file which contains the administrator name and password in cleartext, then retrieving the file from the web server before the Greymatter administrator performs a "Clear And Exit" action.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 4 |
References
- http://marc.info/?l=bugtraq&m=101465343308249&w=2
- http://marc.info/?l=bugtraq&m=101465343308249&w=2
- http://www.dangerousmonkey.com/dangblog/dangarch/00000051.htm
- http://www.dangerousmonkey.com/dangblog/dangarch/00000051.htm
- http://www.iss.net/security_center/static/8277.php
- http://www.iss.net/security_center/static/8277.php
- http://www.securityfocus.com/bid/4169
- http://www.securityfocus.com/bid/4169