JPEGX Wizard Password Bypass Vulnerability
BID:7298
Info
JPEGX Wizard Password Bypass Vulnerability
| Bugtraq ID: | 7298 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Apr 07 2003 12:00AM |
| Updated: | Apr 07 2003 12:00AM |
| Credit: | Discovery of this vulnerability has been credited to JeiAr <[email protected]>. |
| Vulnerable: |
Jpegx Jpegx 2.0.3 |
| Not Vulnerable: | |
Discussion
JPEGX Wizard Password Bypass Vulnerability
JpegX has been reported prone to a password bypass vulnerability.
It has been reported that, when no password credentials are supplied if using the JpegX wizard to decrypt encrypted data contained in JPEG files JpegX will decipher the file regardless.
This vulnerability may lead to sensitive information disclosure.
JpegX has been reported prone to a password bypass vulnerability.
It has been reported that, when no password credentials are supplied if using the JpegX wizard to decrypt encrypted data contained in JPEG files JpegX will decipher the file regardless.
This vulnerability may lead to sensitive information disclosure.
Exploit / POC
JPEGX Wizard Password Bypass Vulnerability
There is no exploit required.
There is no exploit required.
References
JPEGX Wizard Password Bypass Vulnerability
References:
References:
- Jpegx Homepage (Jpegx)
- JpegX 2.0.0.3 Password Bypass Vulnerability (JeiAr
)