4.6
CVSSv2

CVE-2005-1606

Published: 16/05/2005 Updated: 11/07/2017
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
VMScore: 465
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

H-Sphere Winbox 2.4.2 and 2.4.3 RC1 stores sensitive information such as username and password in plaintext in world-readable log files, which allows local users to gain privileges.

Vulnerable Product Search on Vulmon Subscribe to Product

positive software h-sphere winbox 2.4.2_patch_4

positive software h-sphere winbox 2.4.3_rc1

Exploits

source: wwwsecurityfocuscom/bid/13559/info It is reported that Positive Software H-Sphere Winbox stores user account information in a plaintext format inside of application log files As a result, user credentials could be exposed to other local users who have permissions to access the log files C:\HSphereNET\log\actionlog C:\HSpher ...