20001122 CyberPatrol - poor credit card protectionmailing list
http://archives.neohapsis.com/archives/bugtraq/2000-11/0323.html CVE-2000-1173
Microsys CyberPatrol 4.0 4.003/4.0 4.005 - Insecure Registration
Record summary
CVE-2000-1173 has a selected CVSS score of 5.0; EIP currently links 1 catalogued exploit.
Description
Microsys CyberPatrol uses weak encryption (trivial encoding) for credit card numbers and uses no encryption for the remainder of the information during registration, which could allow attackers to sniff network traffic and obtain this sensitive information.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBMicrosys CyberPatrol 4.0 4.003/4.0 4.005 - Insecure RegistrationExploitDB exploitby Joey MaierNot analyzed1 file
References
31977vdb entry
http://www.securityfocus.com/bid/1977 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2000-1173