12Planet Chat Server Administration Authentication ClearText Credential Disclosure

This script is Copyright (C) 2003-2014 Tenable Network Security, Inc.


Synopsis :

The remote web server contains a Java Application that is affected by
a cleartext authentication vulnerability.

Description :

The remote host is running 12Planet Chat Server - a web-based chat
server written in Java.

The connection to this server is done over clear text, which means that
an attacker who can sniff the data going to this host could obtain the
administrator password of the website, and use it to gain unauthorized
access to this chat server.

See also :

http://www.nessus.org/u?9f7511d2

Solution :

Add an HTTPS layer to the administration console for the deployment of
production servers.

Risk factor :

Low / CVSS Base Score : 1.8
(CVSS2#AV:A/AC:H/Au:N/C:P/I:N/A:N)
CVSS Temporal Score : 1.8
(CVSS2#E:H/RL:U/RC:ND)
Public Exploit Available : true

Family: Web Servers

Nessus Plugin ID: 11591 (12planet_chat_server_plaintext_password.nasl)

Bugtraq ID: 7354

CVE ID: