Citrix Program Neighborhood client before 9.150 caches the user password in plaintext in the GUI while asterisks are used to visually obfuscate the password, which allows attackers with access to the session to obtain the password by using a tool to directly access the field.
References
Link | Resource |
---|---|
http://support.citrix.com/article/CTX108108 | Exploit Vendor Advisory |
http://securitytracker.com/id?1015372 | Exploit |
Configurations
Information
Published : 2005-12-20 03:03
Updated : 2008-09-05 13:56
NVD link : CVE-2005-4412
Mitre link : CVE-2005-4412
JSON object : View
CWE
Products Affected
citrix
- program_neighborhood_client