Vulnerabilities > CVE-2007-6330 - Unspecified vulnerability in Meridian Software Prolog Manager 2007/7.0/7.5
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Meridian Prolog Manager 2007, and 7.5 and earlier, sends all usernames and passwords to the client in a (1) cleartext or (2) weakly encrypted format to support client-side login authentication, which makes it easier for remote attackers to obtain database access by capturing credentials via a man-in-the-middle attack.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 3 |
References
- http://osvdb.org/42634
- http://osvdb.org/42634
- http://secunia.com/advisories/28065
- http://secunia.com/advisories/28065
- http://www.kb.cert.org/vuls/id/120593
- http://www.kb.cert.org/vuls/id/120593
- http://www.kb.cert.org/vuls/id/MIMG-77FL3T
- http://www.kb.cert.org/vuls/id/MIMG-77FL3T
- http://www.securityfocus.com/archive/1/484886/100/0/threaded
- http://www.securityfocus.com/archive/1/484886/100/0/threaded
- http://www.securityfocus.com/bid/26826
- http://www.securityfocus.com/bid/26826
- https://exchange.xforce.ibmcloud.com/vulnerabilities/38996
- https://exchange.xforce.ibmcloud.com/vulnerabilities/38996