Vulnerabilities > CVE-2009-2429 - Credentials Management vulnerability in Mcafee Smartfilter 4.2.1.00
Attack vector
LOCAL Attack complexity
LOW Privileges required
NONE Confidentiality impact
PARTIAL Integrity impact
PARTIAL Availability impact
PARTIAL Summary
SmartFilter Web Gateway Security 4.2.1.00 stores user credentials in cleartext in admin_backup.xml files and uses insecure permissions for these files, which allows local users to gain privileges. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Common Weakness Enumeration (CWE)
Seebug
bulletinFamily | exploit |
description | Bugraq ID: 35756 CVE ID:CVE-2009-2312 CVE-2009-2429 CNCVE ID:CNCVE-20092312 CNCVE-20092429 McAfee SmartFilter是一款网站过滤解决方案。 McAfee SmartFilter存在设计问题,本地攻击者可以利用漏洞获得敏感信息。 用于proxy服务器验证的SmartFilter user ID的用户名和明文文本密码保存在c:\Program Files\Secure Computing\Smartfilter Administration\server目录下的config子目录中,利用这些敏感信息可对系统进行进一步攻击。 0 McAfee SmartFilter 4.2.1.00 厂商解决方案 目前没有解决方案提供: http://www.securecomputing.com/ |
id | SSV:11863 |
last seen | 2017-11-19 |
modified | 2009-07-23 |
published | 2009-07-23 |
reporter | Root |
title | McAfee SmartFilter信息泄漏漏洞 |