Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2011-2082
Description:The vulnerable-passwords script in Best Practical Solutions RT 3.x before 3.8.12 and 4.x before 4.0.6 does not update the password-hash algorithm for disabled user accounts, which makes it easier for context-dependent attackers to determine cleartext passwords, and possibly use these passwords after accounts are re-enabled, via a brute-force attack on the database. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-0009.
Test IDs: 1.3.6.1.4.1.25623.1.0.71358   1.3.6.1.4.1.25623.1.0.72206  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2011-2082
BugTraq ID: 53660
http://www.securityfocus.com/bid/53660
http://lists.bestpractical.com/pipermail/rt-announce/2012-May/000203.html
http://lists.bestpractical.com/pipermail/rt-announce/2012-May/000204.html
http://lists.bestpractical.com/pipermail/rt-announce/2012-May/000202.html
http://secunia.com/advisories/49259




© 1998-2025 E-Soft Inc. All rights reserved.