WebcamNow Plain Text Password Storage Weakness
BID:7884
Info
WebcamNow Plain Text Password Storage Weakness
| Bugtraq ID: | 7884 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Jun 12 2003 12:00AM |
| Updated: | Jun 12 2003 12:00AM |
| Credit: | This vulnerability was discovered by Donnie Werner. |
| Vulnerable: |
WebcamNow WebcamNow |
| Not Vulnerable: | |
Discussion
WebcamNow Plain Text Password Storage Weakness
WebcamNow stores usernames and associated passwords using plaintext format, in the Windows registry. As a result, these credentials could be exposed to other local users who have the permissions to access the registry.
WebcamNow stores usernames and associated passwords using plaintext format, in the Windows registry. As a result, these credentials could be exposed to other local users who have the permissions to access the registry.
Exploit / POC
WebcamNow Plain Text Password Storage Weakness
There is no exploit code required.
There is no exploit code required.
Solution / Fix
WebcamNow Plain Text Password Storage Weakness
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.