Mercora IMRadio Plaintext Password Disclosure Weakness
BID:14646
Info
Mercora IMRadio Plaintext Password Disclosure Weakness
| Bugtraq ID: | 14646 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Aug 23 2005 12:00AM |
| Updated: | Aug 23 2005 12:00AM |
| Credit: | Kozan and ATmaCA are credited with the discovery of this vulnerability. |
| Vulnerable: |
Mercora IMRadio 4.0 .0.0 |
| Not Vulnerable: | |
Discussion
Mercora IMRadio Plaintext Password Disclosure Weakness
Mercora IMRadio is prone to a plaintext password disclosure weakness. Registry keys for the application are not encrypted or obfuscated in any way.
A local attacker may monitor the keyboard, CRT and mouse activity of a local administrator and retrieve the usernames and passwords for other users of the affected application.It should be noted that normal user accounts do not have the ability to read these registry keys.
In the event that an attacker gains administrative privileges by some other means, these usernames and passwords could be viewed and recorded to launch further attacks on the affected computer.
Mercora IMRadio is prone to a plaintext password disclosure weakness. Registry keys for the application are not encrypted or obfuscated in any way.
A local attacker may monitor the keyboard, CRT and mouse activity of a local administrator and retrieve the usernames and passwords for other users of the affected application.It should be noted that normal user accounts do not have the ability to read these registry keys.
In the event that an attacker gains administrative privileges by some other means, these usernames and passwords could be viewed and recorded to launch further attacks on the affected computer.
Exploit / POC
Mercora IMRadio Plaintext Password Disclosure Weakness
No exploit is required.
No exploit is required.
Solution / Fix
Mercora IMRadio Plaintext Password Disclosure Weakness
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Mercora IMRadio Plaintext Password Disclosure Weakness
References:
References: