积极预防 及时发现
快速响应 力保恢复
REDIPlus程序, REDI.exe, 把口令和用户名存储在StartLog.txt日志文件中,...
发布时间:2001-06-27 信息来源:管理员

CNCVE编号:CNCVE-20010415 CVE编号:CAN-2001-0415 安全级别:中 漏洞中文描述: REDIPlus程序, REDI.exe, 把口令和用户名存储在StartLog.txt日志文件中,允许本地用户有权访问其他的帐户。 漏洞英文描述: REDIPlus program, REDI.exe, stores passwords and user names in cleartext in the StartLog.txt log file, which allows local users to gain access to other accounts. 漏洞参考: Reference: BUGTRAQ:20010320 Password stored in clear text vulnerability in real time stock trading program Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-03/0275.html Reference: BID:2495 Reference: URL:http://www.securityfocus 系统类型: Unix/Linux Win95/98/ME Win2000/NT 漏洞类型:设计错误