Title : Websense Reporter Module Password Disclosure Vulnerability VUPEN ID : VUPEN/ADV-2008-2819 CVE ID : CVE-2008-4646 CWE ID : CWE-200
Rated as : Low Risk
Remotely Exploitable : No Locally Exploitable : Yes Release Date : 2008-10-15
Technical Description
A vulnerability has been identified in Websense, which could be exploited by local attackers to gain knowledge of sensitive information. This issue is caused due to the Reporter module storing SQL login credentials in plain text in the "CreateDbInstall.log" log file created during the installation process, which could allow malicious users to gain administrative SQL access.