CVE-2007-4961

HIGH

Lindenlab Second Life - Missing Encryption

Title source: rule
STIX 2.1

Description

The login_to_simulator method in Linden Lab Second Life, as used by the secondlife:// protocol handler and possibly other Second Life login mechanisms, sends an MD5 hash in cleartext in the passwd field, which allows remote attackers to login to an account by sniffing the network and then sending this hash to a Second Life authentication server.

References (2)

Core 2
Core References
Broken Link vdb-entry x_refsource_osvdb
http://osvdb.org/45947

Scores

CVSS v3 7.5
EPSS 0.0024
EPSS Percentile 47.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-311
Status published
Products (1)
lindenlab/second_life
Published Sep 18, 2007
Tracked Since Feb 18, 2026