Spytech SpyAnywhere Plaintext Password Vulnerability
BID:2754
Info
Spytech SpyAnywhere Plaintext Password Vulnerability
| Bugtraq ID: | 2754 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 22 2000 12:00AM |
| Updated: | May 22 2000 12:00AM |
| Credit: | Discovered and posted to Bugtraq by SNS Research <[email protected]> on May 22, 2001. |
| Vulnerable: |
Spytech SpyAnywhere 1.50 |
| Not Vulnerable: |
Spytech SpyAnywhere 2.0 |
Discussion
Spytech SpyAnywhere Plaintext Password Vulnerability
A flaw exists in SpyAnywhere which could enable a remote user to gain unauthorized access to the target system.
Authentication credentials are sent to the target system in plain text, therefore; a malicious attacker may be able to easily obtain this information using a sniffer.
A flaw exists in SpyAnywhere which could enable a remote user to gain unauthorized access to the target system.
Authentication credentials are sent to the target system in plain text, therefore; a malicious attacker may be able to easily obtain this information using a sniffer.
Exploit / POC
Spytech SpyAnywhere Plaintext Password Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.