ELOG before 2.5.7 allows remote attackers to bypass authentication and download a configuration file that contains a sensitive write password via a modified URL.
References
Link | Resource |
---|---|
http://sourceforge.net/project/shownotes.php?group_id=40505&release_id=304880 | Patch |
http://midas.psi.ch/elogs/Forum/941 | Vendor Advisory |
http://www.securityfocus.com/bid/12556 | Patch |
Configurations
Configuration 1 (hide)
|
Information
Published : 2005-05-01 21:00
Updated : 2011-03-07 18:20
NVD link : CVE-2005-0440
Mitre link : CVE-2005-0440
JSON object : View
CWE
Products Affected
stefan_ritt
- elog_web_logbook