The Popular URL capability (popularurls.cpp) in Krusader 1.60.0 and 1.70.0-beta1 saves passwords in cleartext in the krusaderrc file when the user enters URLs containing passwords in the panel URL field, which might allow attackers to access other sites.
References
Link | Resource |
---|---|
http://www.krusader.org/phpBB/viewtopic.php?t=1367 | Vendor Advisory |
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=336169 | Patch Vendor Advisory |
http://www.krusader.org/phpBB/viewtopic.php?t=1368 | Patch |
Configurations
Configuration 1 (hide)
|
Information
Published : 2005-11-27 12:03
Updated : 2008-09-05 13:55
NVD link : CVE-2005-3856
Mitre link : CVE-2005-3856
JSON object : View
CWE
Products Affected
krusader
- krusader