1.9
CVSSv2

CVE-2011-5204

Published: 04/10/2012 Updated: 05/10/2012
CVSS v2 Base Score: 1.9 | Impact Score: 2.9 | Exploitability Score: 3.4
VMScore: 195
Vector: AV:L/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

Akiva WebBoard 8.x stores passwords in plaintext, which allows local users to obtain sensitive information by reading from the database.

Vulnerable Product Search on Vulmon Subscribe to Product

akiva webboard 8.0

Exploits

# Exploit Title: Akiva Webboard 8x SQL Injection + Plaintext Passwords in Profiles # Google Dork: " /Powered by WebBoard 8"/ # Date: 30122011 # Author: Alexander Fuchs # Software Link: wwwakivacom/defaultasp?l=1&id=8 # Version: 8x # Tested on: Windows, Linux # CVE : Nope It is possible to login as administrator with admin'-- ...