CVE-2008-3717 Information

Description

Harmoni before 1.6.0 does not require administrative privileges to list (1) user names or (2) asset ids which allows remote attackers to obtain sensitive information.

Reference

http://secunia.com/advisories/31503 http://sourceforge.net/project/shownotes.php?release_id=619864 http://sourceforge.net/tracker/index.php?func=detail&aid=2040324&group_id=82171&atid=1098812 http://www.securityfocus.com/bid/30706 https://exchange.xforce.ibmcloud.com/vulnerabilities/44485

Share on: