Versions of DocuTrac QuicDoc and Office Therapy that ship with DTISQLInstaller.exe version 1.6.4.0 and prior contain three credentials with known passwords: QDMaster, OTMaster, and sa.
References
Link | Resource |
---|---|
https://blog.rapid7.com/2018/03/14/r7-2018-01-cve-2018-5551-cve-2018-5552-docutrac-office-therapy-installer-hard-coded-credentials-and-cryptographic-salt/ | Exploit Third Party Advisory |
Configurations
Information
Published : 2018-03-19 08:29
Updated : 2019-10-09 16:41
NVD link : CVE-2018-5551
Mitre link : CVE-2018-5551
JSON object : View
CWE
CWE-798
Use of Hard-coded Credentials
Products Affected
docutracinc
- dtisqlinstaller