PT-2001-2621 · Unknown · Autogalaxy

Published

2001-12-31

·

Updated

2024-02-10

·

CVE-2001-1536

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Autogalaxy (affected versions not specified)
Description The issue allows remote attackers to obtain authentication information and gain unauthorized access. This is possible because Autogalaxy stores usernames and passwords in cleartext in cookies, making it easier for attackers to exploit this via sniffing or a cross-site scripting attack.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Cleartext Storage of Sensitive Information

Weakness Enumeration

Related Identifiers

CVE-2001-1536

Affected Products

Autogalaxy