J-Security Center

Title: Positive Software H-Sphere Winbox Sensitive Logfile Content Disclosure Vulnerability

Severity: MODERATE

Description:

Positive Software H-Sphere is a scalable multiserver web hosting solution. It is available for Microsoft Windows platforms.

It is reported that H-Sphere stores user account information in a plaintext format inside of application log files.

Specifically, the passwords are stored in the log files, 'action.log' and 'resources.log'.

As a result, user credentials could be exposed to other local users who have permissions to access the log files.

Affected Products:

  • Positive Software H-Sphere Winbox 2.4.2
  • Positive Software H-Sphere Winbox 2.4.3

References:

Juniper Networks provides this content via a wide variety of sources and production methods. If notified of errors or omissions in the content of this page, Juniper Networks, at its discretion, will modify or remove the page or leave the content as is, depending on various factors including but not limited to the reputation and authority of the party providing the notification. Please use the contact information displayed elsewhere on this page to report any errors or omissions regarding the content on this page.