Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2013-1814
Description:The users/get program in the User RPC API in Apache Rave 0.11 through 0.20 allows remote authenticated users to obtain sensitive information about all user accounts via the offset parameter, as demonstrated by discovering password hashes in the password field of a response.
Test IDs: 1.3.6.1.4.1.25623.1.0.803180  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2013-1814
Bugtraq: 20130312 [CVE-2013-1814] Apache Rave exposes User over API (Google Search)
http://archives.neohapsis.com/archives/bugtraq/2013-03/0078.html
http://www.exploit-db.com/exploits/24744/




© 1998-2025 E-Soft Inc. All rights reserved.