PT-2001-2621 · Unknown · Autogalaxy

CVE-2001-1536

·

Published

2001-12-31

·

Updated

2024-02-10

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Autogalaxy (affected versions not specified)
Description The issue allows remote attackers to obtain authentication information and gain unauthorized access. This is possible because Autogalaxy stores usernames and passwords in cleartext in cookies, making it easier for attackers to exploit this via sniffing or a cross-site scripting attack.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Cleartext Storage of Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2001-1536

Affected Products

Autogalaxy