Vulnerability Description
Trustwave WebDefend Enterprise before 5.0 7.01.903-1.4 stores specific user-account credentials in a MySQL database, which makes it easier for remote attackers to read the event collection table via requests to the management port, a different vulnerability than CVE-2011-0756.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Trustwave | Webdefend | <= 5.0 |
Related Weaknesses (CWE)
References
- http://securitytracker.com/id?1025447
- https://www.trustwave.com/spiderlabs/advisories/TWSL2011-001.txtVendor Advisory
- http://securitytracker.com/id?1025447
- https://www.trustwave.com/spiderlabs/advisories/TWSL2011-001.txtVendor Advisory
FAQ
What is CVE-2011-1906?
CVE-2011-1906 is a vulnerability with a CVSS score of 5.0 (MEDIUM). Trustwave WebDefend Enterprise before 5.0 7.01.903-1.4 stores specific user-account credentials in a MySQL database, which makes it easier for remote attackers to read the event collection table via r...
How severe is CVE-2011-1906?
CVE-2011-1906 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2011-1906?
Check the references section above for vendor advisories and patch information. Affected products include: Trustwave Webdefend.