CVE-2005-4661 Information

Description

The notifyendsubs cron job in Campsite before 2.3.3 sends an e-mail message containing a certain unencrypted MySQL password which allows remote attackers to sniff the password.

Reference

http://secunia.com/advisories/17528 http://sourceforge.net/project/shownotes.php?release_id=367403&group_id=66936 http://www.osvdb.org/20698 https://exchange.xforce.ibmcloud.com/vulnerabilities/23106

Share on: