Vulnerabilities > CVE-2006-5018 - Information Disclosure vulnerability in ContentKeeper Accounts Password

047910
CVSS 4.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
SINGLE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
network
low complexity
contentkeeper-technologies

Summary

ContentKeeper 123.25 and earlier places passwords in cleartext in an INPUT element in cgi-bin/ck/changepw.cgi, which allows remote authenticated users to obtain passwords via this URI.

Vulnerable Configurations

Part Description Count
Application
Contentkeeper_Technologies
1