ID |
CVE-2002-0235
|
Sažetak |
Castelle FaxPress, possibly 6.3 and other versions, when configured to use the Network print queue, allows attackers to obtain the username and password by submitting an incorrect login, which causes Faxpress to leak the correct username and password in plaintext in an error event. |
Reference |
|
CVSS |
Base: | 7.5 |
Impact: | 6.4 |
Exploitability: | 10.0 |
|
Pristup |
Vektor | Složenost | Autentikacija |
NETWORK |
LOW |
NONE |
|
Impact |
Povjerljivost | Cjelovitost | Dostupnost |
PARTIAL |
PARTIAL |
PARTIAL |
|
CVSS vektor |
AV:N/AC:L/Au:N/C:P/I:P/A:P |
Zadnje važnije ažuriranje |
05-09-2008 - 20:27 |
Objavljeno |
29-05-2002 - 04:00 |