CVE-2008-4165: Medium severity kolab groupware server vulnerability
admin/user/createuser.php in Kolab Groupware Server 1.0.0 places a user password in an HTTP GET request, which allows local administrators, and possibly remote attackers, to obtain cleartext passwords by reading the sslaccesslog file or the referer string.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2008-4165?
CVE-2008-4165 is considered a moderate severity vulnerability due to the potential exposure of user passwords.
How do I fix CVE-2008-4165?
To fix CVE-2008-4165, it is recommended to avoid using HTTP GET requests for sensitive data and implement secure password handling practices.
Who is affected by CVE-2008-4165?
CVE-2008-4165 affects users of Kolab Groupware Server version 1.0.0.
What are the risks associated with CVE-2008-4165?
The risks associated with CVE-2008-4165 include the potential for local administrators or attackers to obtain cleartext passwords from logs or the referer string.
Can CVE-2008-4165 be exploited remotely?
Yes, although CVE-2008-4165 can be exploited locally, there is a possibility for remote attackers to access the cleartext passwords if the conditions permit.