CVE-2008-5107
Published Nov 17, 2008
Last updated 7 years ago
Overview
- Description
- The installation process for Citrix Presentation Server 4.5 and Desktop Server 1.0, when MSI logging is enabled, stores database credentials in MSI log files, which allows local users to obtain these credentials by reading the log files.
- Source
- cve@mitre.org
- NVD status
- Analyzed
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 1.9
- Impact score
- 2.9
- Exploitability score
- 3.4
- Vector string
- AV:L/AC:M/Au:N/C:P/I:N/A:N
Weaknesses
- nvd@nist.gov
- CWE-200
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:citrix:desktop_server:1.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "08AEEC3F-E8DD-4535-98D2-4CFD83439A69" }, { "criteria": "cpe:2.3:a:citrix:presentation_server:4.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "BD859173-2ACD-4C60-8EF4-5B0434EA8244" } ], "operator": "OR" } ] } ]