Nessus 2.0.10a stores account passwords in plaintext in .nessusrc files, which allows local users to obtain passwords. NOTE: the original researcher reports that the vendor has disputed this issue
Weaknesses in this category are related to the management of credentials.
Link | Tags |
---|---|
http://archives.neohapsis.com/archives/fulldisclosure/2004-03/1363.html | mailing list |
https://exchange.xforce.ibmcloud.com/vulnerabilities/15644 | vdb entry |
http://securitytracker.com/id?1009575 | vdb entry |
http://www.osvdb.org/4816 | vdb entry |