First published: Tue Oct 10 2006(Updated: )
Adobe Contribute Publishing Server leaks the administrator password in logs that are created during product installation, which allows local users to gain privileges to the server.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Contribute |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-5199 is categorized as a high severity vulnerability due to potential privilege escalation.
To fix CVE-2006-5199, ensure that the server logs do not store sensitive information and regularly audit logs for sensitive data.
Users of Adobe Contribute Publishing Server versions that log the administrator password during installation are affected by CVE-2006-5199.
The risks include unauthorized access to the server by local users due to exposed administrator passwords in logs.
CVE-2006-5199 is a local vulnerability, allowing local users to exploit the log files for privilege escalation.