Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
BindView NetInventory 1.0, when used with NetRC 1.0, allows local users to read sensitive information (passwords) by deleting the HOSTCFG._NI file and forcing an audit, which rewrites the HOSTCFG._NI to HOSTCFG.INI and stores the passwords in cleartext until the audit is complete.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
BindView NetInventory口令泄露漏洞
Vulnerability Description
NETinventory是一个由BindView公司发布和维护的财产清单解决方案,运行Windows和MSDOS系统。 NETinventory设计上存在漏洞,可以使本地攻击者得到服务的口令信息。 问题在于服务相关的敏感信息(包括口令)通常储存在文件"HOSTCFG._NI"中,一般情况下是受保护的,当这个文件被删除时,会触发一次新审核,"HOSTCFG._NI"文件中的信息会暂时以明文的形式被放入"HOSTCFG.INI"文件里。此时攻击者可能得到此文件中的敏感信息。这个漏洞已经得到BindView的确
CVSS Information
N/A
Vulnerability Type
N/A