Description
iDS6 DSSPro Digital Signage System 6.2 contains a sensitive information disclosure vulnerability that allows remote attackers to intercept authentication credentials through cleartext cookie transmission. Attackers can exploit the autoSave feature to capture user passwords during man-in-the-middle attacks on HTTP communications.
Problem types
Cleartext Transmission of Sensitive Information
Product status
V5.6 B2017.07.12.1757
V4.3
Credits
LiquidWorm as Gjoko Krstic of Zero Science Lab
References
www.zeroscience.mk/en/vulnerabilities/ZSL-2020-5605.php (Zero Science Lab Disclosure (ZSL-2020-5605))
packetstormsecurity.com/files/159915 (Packet Storm Security Exploit Entry)
exchange.xforce.ibmcloud.com/vulnerabilities/191261 (IBM X-Force Vulnerability Exchange)
cxsecurity.com/issue/WLB-2020110023 (CXSecurity Vulnerability Database Entry)
web.archive.org/web/20200919100215/http://www.yerootech.com/ (Archived Yeroo Tech Vendor Homepage)
www.vulncheck.com/...leartext-password-disclosure-via-cookie (VulnCheck Advisory: iDS6 DSSPro Digital Signage System 6.2 Cleartext Password Disclosure via Cookie)