Short Name |
HTTP:INFO-LEAK:POLYCOM |
---|---|
Severity |
Minor |
Recommended |
No |
Category |
HTTP |
Keywords |
Polycom Viewstation - Password Disclosure |
Release Date |
2005/08/02 |
Update Number |
1213 |
Supported Platforms |
idp-4.0+, isg-3.0+, j-series-9.5+, mx-11.4+, srx-12.1+, srx-branch-12.1+, vmx-17.4+, vsrx-12.1+, vsrx3bsd-18.2+ |
This signature detects attempts to exploit a known vulnerability against Polycom Viewstation FX. Attackers can access a configuration file that contains the administration passwords, which is accessible by anyone in Polycom Viewstation FX 4.2.
Polycom ViewStation stores the administrator and software update account passwords in plain text within a HTML file. This file can be accessed through the URI http://<target>/a_security.htm.