Required CVE Record Information
Description
eyeOS 0.8.4 stores usrinfo.xml under the web document root with insufficient access control, which allows remote attackers to obtain user credentials.
References 6 Total
- exchange.xforce.ibmcloud.com: eyeos-usrinfo-information-disclosure(22938) vdb-entry
- securityfocus.com: 15256 vdb-entry
- http://www.thebillygoatcurse.com/advisories/eyeOS_0.8.4_Multiple.pdf
- osvdb.org: 20411 vdb-entry
- secunia.com: 17105 third-party-advisory
- vupen.com: ADV-2005-2259 vdb-entry
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 6 Total
- exchange.xforce.ibmcloud.com: eyeos-usrinfo-information-disclosure(22938) vdb-entryx_transferred
- securityfocus.com: 15256 vdb-entryx_transferred
- http://www.thebillygoatcurse.com/advisories/eyeOS_0.8.4_Multiple.pdf x_transferred
- osvdb.org: 20411 vdb-entryx_transferred
- secunia.com: 17105 third-party-advisoryx_transferred
- vupen.com: ADV-2005-2259 vdb-entryx_transferred