Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

EyeOS User And Password Information Disclosure Vulnerability

eyeOS is prone to an information disclosure vulnerability. This issue is due to a failure in the application to do proper access validation before granting access to sensitive and privileged information.

An attacker can exploit this vulnerability to obtain a list of valid usernames and their corresponding encrypted passwords. Information obtained may aid in further attacks against the underlying system; other attacks are also possible.







 

Privacy Statement
Copyright 2009, SecurityFocus