Vulnerabilities > CVE-2006-4676 - Information Disclosure vulnerability in TIBCO Rendezvous Rvrd.DB

047910
CVSS 1.2 - LOW
Attack vector
LOCAL
Attack complexity
HIGH
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
local
high complexity
tibco
exploit available

Summary

TIBCO RendezVous 7.4.11 and earlier logs base64-encoded usernames and passwords in rvrd.db, which allows local users to obtain sensitive information by decoding the log file.

Vulnerable Configurations

Part Description Count
Application
Tibco
1

Exploit-Db

descriptionTIBCO Rendezvous <= 7.4.11 Password Extractor Local Exploit. CVE-2006-4676. Local exploit for windows platform
fileexploits/windows/local/2284.c
idEDB-ID:2284
last seen2016-01-31
modified2006-09-01
platformwindows
port
published2006-09-01
reporterAndres Tarasco
sourcehttps://www.exploit-db.com/download/2284/
titleTIBCO Rendezvous <= 7.4.11 Password Extractor Local Exploit
typelocal