Intellisol Xpede 4.1 stores passwords in plaintext in a Javascript "session timeout" re-authentication capability, which could allow local users with access to gain privileges of other Xpede users by reading the password from the source file, e.g. from the browser's cache.
References
| Link | Resource |
|---|---|
| http://www.iss.net/security_center/static/8612.php | Vendor Advisory |
| http://www.securityfocus.com/bid/4346 | Exploit Vendor Advisory |
| http://www.securityfocus.com/archive/1/263485 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2002-08-11 21:00
Updated : 2008-09-05 13:28
NVD link : CVE-2002-0487
Mitre link : CVE-2002-0487
JSON object : View
CWE
Products Affected
workforceroi
- xpede


