Vulnerabilities > CVE-2005-1606 - Unspecified vulnerability in Positive Software H-Sphere Winbox 2.4.2Patch4/2.4.3Rc1
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
H-Sphere Winbox 2.4.2 and 2.4.3 RC1 stores sensitive information such as username and password in plaintext in world-readable log files, which allows local users to gain privileges.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 2 |
References
- http://exploitlabs.com/files/advisories/EXPL-A-2005-007-hsphere.txt
- http://exploitlabs.com/files/advisories/EXPL-A-2005-007-hsphere.txt
- http://secunia.com/advisories/15287
- http://secunia.com/advisories/15287
- http://www.osvdb.org/16239
- http://www.osvdb.org/16239
- http://www.psoft.net/misc/hsphere_winbox_security_update_passwd.html
- http://www.psoft.net/misc/hsphere_winbox_security_update_passwd.html
- http://www.securityfocus.com/bid/13559
- http://www.securityfocus.com/bid/13559
- https://exchange.xforce.ibmcloud.com/vulnerabilities/20522
- https://exchange.xforce.ibmcloud.com/vulnerabilities/20522