CVE-2004-1549

Properties

Published:
30.12.2004
Updated:
20.10.2005
Patch available:
Severity:
Low
  • CVSS vector:
    (AV:R/AC:L/Au:NR/C:C/I:N/A:N/B:N) Approximated
    Product:
    ActivePost: ActivePost Standard

    Vulnerability description

    The conference menu in ActivePost Standard 3.1 sends passwords of password-protected rooms in cleartext, which could allow remote attackers to gain sensitive information by sniffing the network connection.

    References:

    BID: http://www.securityfocus.com/bid/11244
    SECUNIA: http://secunia.com/advisories/12642/
    XF: http://xforce.iss.net/xforce/xfdb/17486
    Luigi Auriemma: http://aluigi.altervista.org/adv/actp-adv.txt
    SECTRACK: http://securitytracker.com/id?1011406
    BUGTRAQ: http://marc.theaimsgroup.com/?l=bugtraq&m=109597139011373&w=2