20040604 [CYSA-0329] Password recovery vulnerability in FoolProof Security 3.9.x for Windows 95/9mailing list
http://archives.neohapsis.com/archives/fulldisclosure/2004-06/0081.html CVE-2004-2555
SmartStuff FoolProof Security Program 3.9.x - Administrative Password Recovery
Record summary
CVE-2004-2555 has a selected CVSS score of 2.1; EIP currently links 1 catalogued exploit.
Description
Riverdeep FoolProof Security 3.9.x on Windows 98 and Windows ME uses weak cryptography (arithmetic and XOR operations) to relate the Control password to the Administrator password, which allows local users to calculate the Administrator password if they know the Control password and password recovery key.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBSmartStuff FoolProof Security Program 3.9.x - Administrative Password RecoveryExploitDB exploitby Cyrillium SecurityNot analyzed1 file
References
611790Third-party advisory
http://secunia.com/advisories/11790 6735vdb entry
http://www.osvdb.org/6735 10467vdb entry
http://www.securityfocus.com/bid/10467 foolproof-admin-password-recovery(16327)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/16327 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2004-2555