CVE-2014-0347
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The Settings module in Websense Triton Unified Security Center 7.7.3 before Hotfix 31, Web Filter 7.7.3 before Hotfix 31, Web Security 7.7.3 before Hotfix 31, Web Security Gateway 7.7.3 before Hotfix 31, and Web Security Gateway Anywhere 7.7.3 before Hotfix 31 allows remote authenticated users to read cleartext passwords by replacing type="password" with type="text" in an INPUT element in the (1) Log Database or (2) User Directories component.
El módulo de configuraciones en Websense Triton Unified Security Center 7.7.3 anterior a Hotfix 31, Web Filter 7.7.3 anterior a Hotfix 31, Web Security 7.7.3 anterior a Hotfix 31, Web Security Gateway 7.7.3 anterior a Hotfix 31 y Web Security Gateway Anywhere 7.7.3 anterior a Hotfix 31 permite a usuarios remotos autenticados leer contraseñas en texto claro mediante la sustitución type="password" con type="text" en un elemento INPUT en el componente (1) Log Database o (2) User Directories.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2013-12-05 CVE Reserved
- 2014-04-12 CVE Published
- 2024-02-23 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-255: Credentials Management Errors
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
http://www.kb.cert.org/vuls/id/568252 | Third Party Advisory | |
https://www.websense.com/content/mywebsense-hotfixes.aspx?patchid=894&prodidx=20&osidx=0&intidx=0&versionidx=0 | X_refsource_confirm |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Websense Search vendor "Websense" | Triton Unified Security Center Search vendor "Websense" for product "Triton Unified Security Center" | 7.7.3 Search vendor "Websense" for product "Triton Unified Security Center" and version "7.7.3" | - |
Affected
| ||||||
Websense Search vendor "Websense" | Triton Web Filter Search vendor "Websense" for product "Triton Web Filter" | 7.7.3 Search vendor "Websense" for product "Triton Web Filter" and version "7.7.3" | - |
Affected
| ||||||
Websense Search vendor "Websense" | Triton Web Security Search vendor "Websense" for product "Triton Web Security" | 7.7.3 Search vendor "Websense" for product "Triton Web Security" and version "7.7.3" | - |
Affected
| ||||||
Websense Search vendor "Websense" | Triton Web Security Gateway Search vendor "Websense" for product "Triton Web Security Gateway" | 7.7.3 Search vendor "Websense" for product "Triton Web Security Gateway" and version "7.7.3" | - |
Affected
| ||||||
Websense Search vendor "Websense" | Triton Web Security Gateway Anywhere Search vendor "Websense" for product "Triton Web Security Gateway Anywhere" | 7.7.3 Search vendor "Websense" for product "Triton Web Security Gateway Anywhere" and version "7.7.3" | - |
Affected
|