PT-2006-5520 · Scarybear · Scarybear Pocketexpense Pro
Seth Fogie
·
Published
2006-09-13
·
Updated
2018-10-17
·
CVE-2006-4745
CVSS v2.0
3.6
Low
| Vector | AV:L/AC:L/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
ScaryBear PocketExpense Pro version 3.9.1
Description
The issue allows local users to disable authentication and access a data file by modifying a certain value in the file header, because the file's contents are stored in plaintext and protected by an internally recorded key.
Recommendations
For ScaryBear PocketExpense Pro version 3.9.1, consider modifying the application to store data files securely, such as by using encryption, and ensure that authentication mechanisms are properly implemented to prevent unauthorized access.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Scarybear Pocketexpense Pro