Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
ZOHO WebNMS Framework 5.2 and 5.2 SP1 use a weak obfuscation algorithm to store passwords, which allows context-dependent attackers to obtain cleartext passwords by leveraging access to WEB-INF/conf/securitydbData.xml. NOTE: this issue can be combined with CVE-2016-6601 for a remote exploit.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
ZOHO WebNMS Framework 安全漏洞
Vulnerability Description
ZOHO WebNMS Framework是美国卓豪(ZOHO)公司的一套用于构建网络管理应用的框架。 ZOHO WebNMS Framework 5.2和5.2 SP1版本中存在安全漏洞,该漏洞源于程序使用弱模糊算法储存密码。攻击者可借助WEB-INF/conf/securitydbData.xml文件的访问权限利用该漏洞获取明文密码。
CVSS Information
N/A
Vulnerability Type
N/A