Intellisol Xpede 4.1 stores passwords in plaintext in a Javascript "session timeout" re-authentication capability, which could allow local users with access to gain privileges of other Xpede users by reading the password from the source file, e.g. from the browser's cache.
Link | Tags |
---|---|
http://www.securityfocus.com/archive/1/263485 | mailing list vendor advisory |
http://www.iss.net/security_center/static/8612.php | vdb entry vendor advisory |
http://www.securityfocus.com/bid/4346 | exploit vdb entry vendor advisory |