5
CVSSv2

CVE-2011-4432

Published: 10/11/2011 Updated: 14/02/2012
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

www/include/configuration/nconfigObject/contact/DB-Func.php in Merethis Centreon prior to 2.3.2 does not use a salt during calculation of a password hash, which makes it easier for context-dependent malicious users to determine cleartext passwords via a rainbow-table approach.

Vulnerable Product Search on Vulmon Subscribe to Product

merethis centreon 1.4.2.1

merethis centreon 1.4.2.2

merethis centreon 2.0

merethis centreon 2.1.2

merethis centreon 2.1.3

merethis centreon 2.2.1

merethis centreon 2.2.2

merethis centreon 1.4.1

merethis centreon 1.4.2

merethis centreon 2.0.1

merethis centreon 2.0.2

merethis centreon 2.1.12

merethis centreon 2.1.13

merethis centreon 2.1.9

merethis centreon 2.2

merethis centreon 2.3.0

merethis centreon

merethis centreon 1.4.2.3

merethis centreon 1.4.2.4

merethis centreon 1.4.2.5

merethis centreon 2.1.0

merethis centreon 2.1.1

merethis centreon 2.1.4

merethis centreon 2.1.5

merethis centreon 2.1.6

merethis centreon 1.4

merethis centreon 1.4.2.6

merethis centreon 1.4.2.7

merethis centreon 2.1.10

merethis centreon 2.1.11

merethis centreon 2.1.7

merethis centreon 2.1.8