|
|
|
![]() |
Vulnerability Note VU#586720JetboxOne leaves account database unencryptedOverviewJetboxOne does not encrypt information in the account information database. Any user with the ability to query the database may be able to view confidential account information.I. DescriptionJetboxOne is an open-source content management system that is written in PHP. An information disclosure vulnerability exists because JetboxOne does not encrypt account information stored in the admin (user) and webuser (standard user) tables of a MySQL database.II. ImpactAny user with the ability to query the database may be able to view confidential account information. This may lead to unauthorized access to other accounts.III. SolutionThe CERT/CC is currently unaware of a practical solution to this problem.Systems Affected
Referenceshttp://echo.or.id/adv/adv03-y3dips-2004.txt
This vulnerability was publicly reported by y3dips. This document was written by Jeff Gennari.
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
|||||||||||||||||||||||||||||||||||||
|
|||||||||||||||||||||||||||||||||||||||