CVE-2004-2398: Low severity Netenberg Fantastico De Luxe vulnerability
Netenberg Fantastico De Luxe 2.8 uses database file names that contain the associated usernames, which allows local users to determine valid usernames and conduct brute force attacks by reading the file names from /var/lib/mysql, which is assigned world-readable permissions by cPanel 9.3.0 R5.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2004-2398?
CVE-2004-2398 has a medium severity level due to its potential for username enumeration and subsequent brute force attacks.
How do I fix CVE-2004-2398?
To fix CVE-2004-2398, remove world-readable permissions from the database directory or upgrade to a version of Fantastico De Luxe that addresses this vulnerability.
Who is affected by CVE-2004-2398?
CVE-2004-2398 primarily affects users of Netenberg Fantastico De Luxe version 2.8 running on cPanel 9.3.0 R5 or similar configurations.
What can attackers do with CVE-2004-2398?
Attackers can use CVE-2004-2398 to determine valid usernames on the system which can lead to credential guessing or brute force attacks.
Is there a workaround for CVE-2004-2398?
A temporary workaround for CVE-2004-2398 includes changing the permissions of the MySQL directory to restrict access to only necessary users.