Vulnerabilities > CVE-2016-2296 - 7PK - Security Features vulnerability in Meteocontrol products
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
HIGH Integrity impact
HIGH Availability impact
LOW Summary
Meteocontrol WEB'log Basic 100, Light, Pro, and Pro Unlimited does not require authentication for "post-admin" login pages, which allows remote attackers to obtain sensitive information or modify data via unspecified vectors.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 4 |
Common Weakness Enumeration (CWE)
Exploit-Db
description | Meteocontrol WEB’log - Admin Password Disclosure. CVE-2016-2296. Webapps exploits for multiple platform |
file | exploits/multiple/webapps/39822.rb |
id | EDB-ID:39822 |
last seen | 2016-05-17 |
modified | 2016-05-17 |
platform | multiple |
port | |
published | 2016-05-17 |
reporter | Karn Ganeshen |
source | https://www.exploit-db.com/download/39822/ |
title | Meteocontrol WEB’log - Admin Password Disclosure |
type | webapps |
Metasploit
description | This module exploits an authentication bypass vulnerability in Meteocontrol WEBLog appliances (software version < May 2016 release) to extract Administrator password for the device management portal. |
id | MSF:AUXILIARY/SCANNER/HTTP/METEOCONTROL_WEBLOG_EXTRACTADMIN |
last seen | 2019-12-17 |
modified | 2017-07-24 |
published | 2017-01-06 |
references | |
reporter | Rapid7 |
source | https://github.com/rapid7/metasploit-framework/blob/master//modules/auxiliary/scanner/http/meteocontrol_weblog_extractadmin.rb |
title | Meteocontrol WEBlog Password Extractor |
Packetstorm
data source | https://packetstormsecurity.com/files/download/137099/meteocontrol-extract.rb.txt |
id | PACKETSTORM:137099 |
last seen | 2016-12-05 |
published | 2016-05-17 |
reporter | Karn Ganeshen |
source | https://packetstormsecurity.com/files/137099/Meteocontrol-WEBLog-Password-Extractor.html |
title | Meteocontrol WEBLog Password Extractor |