vendor:
UPB
by:
Alberto Trivero
7.5
CVSS
HIGH
Password Decryption
311
CWE
Product Name: UPB
Affected Version From: UPB <= 1.9.6
Affected Version To: N/A
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2006
Passwords Decrypter for UPB <= 1.9.6
This exploit is used to decrypt the passwords of UPB <= 1.9.6. It uses a perl script to decrypt the passwords from the users.dat file. The script takes the target URL and the username as input and decrypts the password of the given username.
Mitigation:
Upgrade to the latest version of UPB.