PT-2006-5520 · Scarybear · Scarybear Pocketexpense Pro

Seth Fogie

·

Publicado

2006-09-13

·

Atualizado

2018-10-17

·

CVE-2006-4745

CVSS v2.0

3.6

Baixa

VetorAV:L/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions ScaryBear PocketExpense Pro version 3.9.1
Description The issue allows local users to disable authentication and access a data file by modifying a certain value in the file header, because the file's contents are stored in plaintext and protected by an internally recorded key.
Recommendations For ScaryBear PocketExpense Pro version 3.9.1, consider modifying the application to store data files securely, such as by using encryption, and ensure that authentication mechanisms are properly implemented to prevent unauthorized access.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-4745

Produtos afetados

Scarybear Pocketexpense Pro