vendor:
tftgallery
by:
undefined1_
7,5
CVSS
HIGH
Password Hash Disclosure
200
CWE
Product Name: tftgallery
Affected Version From: 0.10
Affected Version To: 0.10
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
undefined1_
tftgallery 0.10 exploit
This exploit allows an attacker to retrieve the admin password hash from the tftgallery 0.10 application. The exploit sends a GET request to the admin/passwd page and retrieves the password hash from the response. The plaintext password can then be retrieved using John the Ripper.
Mitigation:
Upgrade to the latest version of tftgallery.