Gyach Enhanced (Gyach-E) before 1.0.0 stores passwords in plaintext, which allows attackers to obtain user passwords by reading the configuration file.
Weaknesses in this category are related to the management of credentials.
Link | Tags |
---|---|
http://www.osvdb.org/8834 | vdb entry |
http://www.phrozensmoke.com/projects/pyvoicechat/changelog.php | patch |