Note-A-Day Lets Remote Users Access Authentication Information
|
|
SecurityTracker Alert ID: 1015539 |
|
SecurityTracker URL: http://securitytracker.com/id/1015539
|
|
CVE Reference:
GENERIC-MAP-NOMATCH
(Links to External Site)
|
Date: Jan 25 2006
|
Impact:
Disclosure of authentication information
|
Exploit Included: Yes
|
Version(s): 2.1
|
Description:
Aliaksandr Hartsuyeu of eVuln reported a vulnerability in Note-A-Day. A remote user can obtain encrypted authentication information.
By default the 'archive' directory is not protected. A remote user can access files in that directory, including encrypted password files.
A demonstration exploit URL is provided:
http://[target]/noteday/archive/.phpass-admin
The original advisory is available at:
http://evuln.com/vulns/44/summary.html
|
Impact:
A remote user can obtain encrypted authentication information.
|
Solution:
No solution was available at the time of this entry.
|
Vendor URL: noteaday.com/ (Links to External Site)
|
Cause:
Access control error
|
Underlying OS:
Linux (Any), UNIX (Any), Windows (Any)
|
|
Message History:
None.
|
Source Message Contents
|
Date: Sun, 22 Jan 2006 18:59:37 +0300
Subject: [eVuln] Note-A-Day Weblog Sensitive Information Disclosure
|
New eVuln Advisory:
Note-A-Day Weblog Sensitive Information Disclosure
http://evuln.com/vulns/44/summary.html
--------------------Summary----------------
Software: Note-A-Day
Sowtware's Web Site: http://noteaday.com/
Versions: 2.1
Critical Level: Moderate
Type: Sensitive Information Disclosure
Class: Remote
Status: Unpatched
Exploit: Available
Solution: Not Available
Discovered by: Aliaksandr Hartsuyeu (eVuln.com)
eVuln ID: EV0044
-----------------Description---------------
Directory archive is not protected by htaccess in default installiation.
This can be used to retrieve registered user's information including
encrypted passwords.
--------------Exploit----------------------
Admin's encrypted password:
http://host/noteday/archive/.phpass-admin
--------------Solution---------------------
No Patch available.
--------------Credit-----------------------
Original Advisory:
http://evuln.com/vulns/44/summary.html
Discovered by: Aliaksandr Hartsuyeu (eVuln.com)
|
|