NessusWX 1.4.4 stores account passwords in plaintext in .session files, which allows local users to obtain passwords.
Weaknesses in this category are related to the management of credentials.
Link | Tags |
---|---|
http://www.osvdb.org/4814 | vdb entry |
http://www.securityfocus.com/bid/9993 | vdb entry |
http://seclists.org/fulldisclosure/2004/Mar/1343.html | mailing list |
http://securitytracker.com/id?1009577 | vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/15641 | vdb entry |