Exploitation Summary
EIP tracks 2 public exploits for CVE-2005-0823. PoCs published by Kozan.
AI-analyzed exploit summary This exploit reads the iSnooker application's stored credentials from a local file by leveraging a known insecure storage vulnerability. It retrieves the Program Files directory from the Windows Registry and then reads the username and password from a plaintext file.
Description
ThePoolClub (1) iPool and (2) iSnooker 1.6.81 and earlier stores usernames and passwords in cleartext in the MyDetails.txt file, which allows local users to gain privileges.
Exploits (2)
This exploit reads the iSnooker application's stored credentials from a local file by leveraging a known insecure storage vulnerability. It retrieves the Program Files directory from the Windows Registry and then reads the username and password from a plaintext file.
This exploit reads the iPool application's configuration file to disclose locally stored username and password credentials. It leverages predictable file paths and registry queries to locate and extract sensitive data.