19991221 [w00giving '99 #11] IMail's password encryption schememailing list
http://www.securityfocus.com/archive/1/39329 CVE-1999-1497
Ipswitch IMail Server 5.0/5.0.5/5.0.6/5.0.7/5.0.8/6.0 - Weak Password Encryption
Record summary
CVE-1999-1497 has a selected CVSS score of 7.2; EIP currently links 2 catalogued exploits.
Description
Ipswitch IMail 5.0 and 6.0 uses weak encryption to store passwords in registry keys, which allows local attackers to read passwords for e-mail accounts.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 2
Proofs of concept
2Catalogued exploits
ExploitDBIpswitch IMail Server 5.0/5.0.5/5.0.6/5.0.7/5.0.8/6.0 - Weak Password EncryptionExploitDB exploitby Mike DavisNot analyzed1 file
ExploitDBIPSwitch IMail Server 8.1 - Local Password Decryption UtilityExploitDB exploitby AdikNot analyzed1 file
References
3880vdb entry
http://www.securityfocus.com/bid/880 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-1999-1497