|  |  | 
closedb();
?>
| Vulnerability CVE-2011-4432Published: 2011-11-09   Modified: 2012-02-13
 
 
 
	
		| Description: |  
		| www/include/configuration/nconfigObject/contact/DB-Func.php in Merethis Centreon before 2.3.2 does not use a salt during calculation of a password hash, which makes it easier for context-dependent attackers to determine cleartext passwords via a rainbow-table approach. |  See advisories in our WLB2 database:Type:|  | Topic | Author | Date |  
            | 
Med. |  | none | 13.11.2011 | 
 
 CWE-310(Cryptographic Issues)
				 CVSS2 => (AV:N/AC:L/Au:N/C:P/I:N/A:N)| CVSS Base Score | Impact Subscore | Exploitability Subscore |  
							| 5/10 | 2.9/10 | 10/10 | 
 
						| Exploit range | Attack complexity | Authentication |  
						| Remote | Low | No required |  
						| Confidentiality impact | Integrity impact | Availability impact |  
						| Partial | None | None | 
 
|  References: |  
| https://www.trustwave.com/spiderlabs/advisories/TWSL2011-017.txt | 
 |  |  |  Copyright 2025, cxsecurity.com
  
     |  |  |