PT-2015-7104 · Impero · Impero Education Pro
Slipstream/Rol
·
Publicado
2015-09-14
·
Atualizado
2015-09-16
·
CVE-2015-5997
CVSS v2.0
7.8
Alta
| Vetor | AV:N/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Impero Education Pro versions prior to 5105
Description
The issue allows remote attackers to obtain plaintext data by sniffing the network for ciphertext data, due to the use of a hardcoded CBC key and initialization vector derived from a hash of the
Imp3ro string.Recommendations
For versions prior to 5105, update to version 5105 or later to resolve the issue.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Impero Education Pro