20020322 Xpede passwords exposed (2 vuln.)mailing list
http://www.securityfocus.com/archive/1/263485 CVE-2002-0486
WorkforceROI Xpede 4.1/7.0 - Weak Password Encryption
Record summary
CVE-2002-0486 has a selected CVSS score of 7.2; EIP currently links 1 catalogued exploit.
Description
Intellisol Xpede 4.1 uses weak encryption to store authentication information in cookies, which could allow local users with access to the cookies to gain privileges.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBWorkforceROI Xpede 4.1/7.0 - Weak Password EncryptionExploitDB exploitby c3rb3rNot analyzed1 file
References
44344vdb entry
http://www.securityfocus.com/bid/4344 xpede-password-weak-encryption(8614)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/8614 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2002-0486