PT-2007-1441 · Dreameesoft · Dreameesoft Password Master

Publicado

2007-03-10

·

Atualizado

2008-09-05

·

CVE-2006-7163

CVSS v2.0

6.9

Média

VetorAV:L/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions DreameeSoft Password Master version 1.0
Description The issue allows attackers with physical access to read the database contents due to the database being stored in an unencrypted format when the master password is set. This is possible via an unspecified authentication bypass.
Recommendations For DreameeSoft Password Master version 1.0, consider encrypting the database or using an alternative password management solution that stores data securely. As a temporary workaround, restrict physical access to devices where the software is installed to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-7163

Produtos afetados

Dreameesoft Password Master