The installation process for Citrix Presentation Server 4.5 and Desktop Server 1.0, when MSI logging is enabled, stores database credentials in MSI log files, which allows local users to obtain these credentials by reading the log files.
References
Link | Resource |
---|---|
http://www.securityfocus.com/bid/28047 | Third Party Advisory VDB Entry |
http://support.citrix.com/article/CTX116228 | Vendor Advisory |
http://www.vupen.com/english/advisories/2008/0705/references | Permissions Required |
Configurations
Configuration 1 (hide)
|
Information
Published : 2008-11-17 10:18
Updated : 2017-12-04 10:59
NVD link : CVE-2008-5107
Mitre link : CVE-2008-5107
JSON object : View
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
Products Affected
citrix
- presentation_server
- desktop_server