PT-2006-5520 · Scarybear · Scarybear Pocketexpense Pro

Seth Fogie

·

Published

2006-09-13

·

Updated

2018-10-17

·

CVE-2006-4745

CVSS v2.0

3.6

Low

VectorAV:L/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions ScaryBear PocketExpense Pro version 3.9.1
Description The issue allows local users to disable authentication and access a data file by modifying a certain value in the file header, because the file's contents are stored in plaintext and protected by an internally recorded key.
Recommendations For ScaryBear PocketExpense Pro version 3.9.1, consider modifying the application to store data files securely, such as by using encryption, and ensure that authentication mechanisms are properly implemented to prevent unauthorized access.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-4745

Affected Products

Scarybear Pocketexpense Pro