hotfoon4.exe in Hotfoon 4.00 stores user names and passwords in cleartext in the hotfoon2 registry key, which allows local users to gain access to user accounts and steal phone service.
Weaknesses in this category are related to the management of credentials.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/6155 | vdb entry |
http://www.iss.net/security_center/static/10591.php | vdb entry |
http://archives.neohapsis.com/archives/bugtraq/2002-11/0115.html | mailing list exploit |