Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
authenticate_ad_setup_finished.cfm in MediaCAST 8 and earlier allows remote attackers to discover usernames and cleartext passwords by reading the error messages returned for requests that use the UserID parameter.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Inventivetec MediaCast加密问题漏洞
Vulnerability Description
MediaCAST是一个开放的和可互操作的数字内容管理和视频/音频流解决方案。 MediaCast 8及其他版本中存在多个安全漏洞。恶意攻击者可以利用这些漏洞获取敏感信息并执行SQL注入攻击。 (1)当“UserID”设置为有效值,“ClearSession”设置为“1”时,向authenticate_ad_setup_finished.cfm传递的file参数在使用之前没有经过正确验证,攻击者可利用错误消息获取之前存储的Active Directory证书。 (2)向inventivex/mangetr
CVSS Information
N/A
Vulnerability Type
N/A