| Title | DTC の client/new_account_form.php における重要な情報を取得される脆弱性 |
|---|---|
| Summary | Domain Technologie Control (DTC) の client/new_account_form.php の register_user 関数は、電子メールメッセージに平文のパスワードを含むため、重要な情報を取得される脆弱性が存在します。 |
| Possible impacts | 第三者により、ネットワークの傍受により、重要な情報を取得される可能性があります。 |
| Solution | ベンダ情報および参考情報を参照して適切な対策を実施してください。 |
| Publication Date | March 7, 2011, midnight |
| Registration Date | March 27, 2012, 6:42 p.m. |
| Last Update | April 6, 2016, 5:24 p.m. |
| CVSS2.0 : 警告 | |
| Score | 5 |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
| GPLHost |
| Domain Technologie Control 0.32.9 未満 |
| No | Changed Details | Date of change |
|---|---|---|
| 0 | [2012年03月27日] 掲載 [2016年04月06日] ベンダ情報:GPLHost (Fixes: CVE-2011-0436 (password being mailed in clear text)) を追加 ベンダ情報:GPLHost (Fixes: CVE-2011-0436 (password being mailed in clear text)(cherry picked from commit f8e3b2d7cc2da313addc05394568ab9599499285)) を追加 ベンダ情報:Debian (614302) を追加 |
Feb. 17, 2018, 10:37 a.m. |
| Summary | The register_user function in client/new_account_form.php in Domain Technologie Control (DTC) before 0.32.9 includes a cleartext password in an e-mail message, which makes it easier for remote attackers to obtain sensitive information by sniffing the network. |
|---|---|
| Publication Date | March 8, 2011, 6 a.m. |
| Registration Date | Jan. 28, 2021, 4:37 p.m. |
| Last Update | Nov. 21, 2024, 10:23 a.m. |
| Configuration1 | or higher | or less | more than | less than | |
| cpe:2.3:a:gplhost:domain_technologie_control:*:*:*:*:*:*:*:* | 0.32.8 | ||||
| cpe:2.3:a:gplhost:domain_technologie_control:0.29.8:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:gplhost:domain_technologie_control:0.28.9:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:gplhost:domain_technologie_control:0.32.1:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:gplhost:domain_technologie_control:0.25.3:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:gplhost:domain_technologie_control:0.30.6:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:gplhost:domain_technologie_control:0.26.9:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:gplhost:domain_technologie_control:0.29.1:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:gplhost:domain_technologie_control:0.27.3:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:gplhost:domain_technologie_control:0.28.4:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:gplhost:domain_technologie_control:0.32.3:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:gplhost:domain_technologie_control:0.28.10:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:gplhost:domain_technologie_control:0.25.1:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:gplhost:domain_technologie_control:0.30.18:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:gplhost:domain_technologie_control:0.26.8:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:gplhost:domain_technologie_control:0.28.6:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:gplhost:domain_technologie_control:0.28.2:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:gplhost:domain_technologie_control:0.32.2:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:gplhost:domain_technologie_control:0.29.14:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:gplhost:domain_technologie_control:0.29.17:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:gplhost:domain_technologie_control:0.26.7:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:gplhost:domain_technologie_control:0.29.16:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:gplhost:domain_technologie_control:0.30.10:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:gplhost:domain_technologie_control:0.32.6:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:gplhost:domain_technologie_control:0.29.6:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:gplhost:domain_technologie_control:0.28.3:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:gplhost:domain_technologie_control:0.24.6:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:gplhost:domain_technologie_control:0.32.5:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:gplhost:domain_technologie_control:0.29.15:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:gplhost:domain_technologie_control:0.29.10:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:gplhost:domain_technologie_control:0.30.20:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:gplhost:domain_technologie_control:0.30.8:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:gplhost:domain_technologie_control:0.32.7:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:gplhost:domain_technologie_control:0.32.4:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:gplhost:domain_technologie_control:0.25.2:*:*:*:*:*:*:* | |||||