Home arrow News arrow Web Hosting News arrow Flaw Found in H-Sphere, Patched

Sponsors

Banner

Most Viewed Sites

* HostGator
* BlueHost
* Web Hosting Pad
* POWWEB

Flaw Found in H-Sphere, Patched PDF Print E-mail
Thursday, 12 May 2005
Exploitlabs.com reported recently that a flaw had been discovered in the H-Sphere Web hosting automation solution.

When performing administration duties for domain management, H-Sphere writes domain information and the username and password of the administrator in a locally readable log file. According to the report, on Windows servers running H-Sphere, the default install does not restrict permission to this folder, allowing less privileged users to read account information. A hacker could learn the username and password and gain full access to an H-Sphere system.

H-Sphere version 2.4.2 Patch 4 and H-Sphere version 2.4.3 RC 1 are vulnerable to the flaw.

Positive Software (www.psoft.net), the developer of H-Sphere, was notified of the flaw and a patch was released. It can be found at psoft.net/misc/hsphere_winbox_security_update_passwd.html

This vulnerability was discovered and researched by Donnie Werner of Exploitlabs.
Comments (0)add
Write comment
quote
bold
italicize
underline
strike
url
image
quote
quote
smile
wink
laugh
grin
angry
sad
shocked
cool
tongue
kiss
cry
smaller | bigger

security image
Write the displayed characters


busy




Reddit!Del.icio.us!Facebook!Slashdot!Netscape!Technorati!StumbleUpon!Newsvine!Furl!Yahoo!Ma.gnolia!Free social bookmarking plugins and extensions for Joomla! websites! title=
Last Updated ( Monday, 14 April 2008 )
 
< Prev   Next >