PT-2007-1441 · Dreameesoft · Dreameesoft Password Master
Publicado
2007-03-10
·
Atualizado
2008-09-05
·
CVE-2006-7163
CVSS v2.0
6.9
Média
| Vetor | AV:L/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
DreameeSoft Password Master version 1.0
Description
The issue allows attackers with physical access to read the database contents due to the database being stored in an unencrypted format when the master password is set. This is possible via an unspecified authentication bypass.
Recommendations
For DreameeSoft Password Master version 1.0, consider encrypting the database or using an alternative password management solution that stores data securely. As a temporary workaround, restrict physical access to devices where the software is installed to minimize the risk of exploitation.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Dreameesoft Password Master