Description
ACEweb Online Portal 3.5.065 allows unauthenticated SMB hash capture via UNC. By specifying the UNC file path of an external SMB share when uploading a file, an attacker can induce the victim server to disclose the username and password hash of the user executing the ACEweb Online software.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-29460 | ACEweb Online Portal 3.5.065 allows unauthenticated SMB hash capture via UNC. By specifying the UNC file path of an external SMB share when uploading a file, an attacker can induce the victim server to disclose the username and password hash of the user executing the ACEweb Online software. |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-03T04:13:56.660Z
Reserved: 2022-02-07T00:00:00.000Z
Link: CVE-2022-24581
No data.
Status : Modified
Published: 2022-06-02T14:15:37.103
Modified: 2024-11-21T06:50:41.613
Link: CVE-2022-24581
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD