trillian-insecure-password-storage(10092)vdb entry
http://www.iss.net/security_center/static/10092.php CVE-2002-2162
Trillian Instant Messaging 0.x - Credential Encryption
Record summary
CVE-2002-2162 has a selected CVSS score of 4.6; EIP currently links 1 catalogued exploit.
Description
Cerulean Studios Trillian 0.73 and earlier use weak encrypttion (XOR) for storing user passwords in .ini files in the Trillian directory, which allows local users to gain access to other user accounts.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBTrillian Instant Messaging 0.x - Credential EncryptionExploitDB exploitby Coeus GroupNot analyzed1 file
References
420020909 Trillian weakly encrypts saved passwordsmailing list
http://www.securityfocus.com/archive/1/291071 5677vdb entry
http://www.securityfocus.com/bid/5677 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2002-2162