|
|
| |
| A vulnerability was discovered in Quicksilver Forums, which can be exploited by malicious, local users to disclose sensitive information. |
| |
Credit:
The original article can be found at: http://secunia.com/secunia_research/2010-38/
|
| |
Vulnerable Systems:
* Quicksilver Forums version 1.4.2
* PowerDNS Administrator version 1.1.8
* QSF Portal version 1.4.5
The application passes the database password via the command line to the "mysqldump" utility, which may disclose the password via the process list.
Workaround:
Do not use the database backup functionality.
Disclosure Timeline:
24/02/2010 - Vendor of QSF Portal and PowerDNS Administrator notified.
10/03/2010 - Vendor of Quicksilver Forums notified.
17/03/2010 - Public disclosure.
|
|
blog comments powered by
|