CoffeeCup Software Password Wizard Remote Password Retrieval Vulnerability
BID:6995
Info
CoffeeCup Software Password Wizard Remote Password Retrieval Vulnerability
| Bugtraq ID: | 6995 |
| Class: | Configuration Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 01 2003 12:00AM |
| Updated: | Mar 01 2003 12:00AM |
| Credit: | Discovery credited to Rynho Zeros Web <[email protected]>. |
| Vulnerable: |
CoffeeCup Software Password Wizard 4.0 |
| Not Vulnerable: | |
Discussion
CoffeeCup Software Password Wizard Remote Password Retrieval Vulnerability
It has been reported that Password Wizard does not sufficiently protect usernames and passwords. In a default configuration, an attacker may be able to gain access to this information, and thus access to restricted resources.
It has been reported that Password Wizard does not sufficiently protect usernames and passwords. In a default configuration, an attacker may be able to gain access to this information, and thus access to restricted resources.
Exploit / POC
CoffeeCup Software Password Wizard Remote Password Retrieval Vulnerability
No exploit is required for this vulnerability.
No exploit is required for this vulnerability.
References
CoffeeCup Software Password Wizard Remote Password Retrieval Vulnerability
References:
References:
- Password Wizard Product Page (CoffeeCup Software)
- Easy obtaining User+Pass+More on CoffeeCup Password Wizard All Versions (Rynho Zeros Web
)