Crafty Syntax Live Help (CSLH) 2.14.6 and earlier stores passwords in cleartext in a MySQL database, which allows context-dependent attackers to obtain sensitive information.
Weaknesses in this category are related to the management of credentials.
Link | Tags |
---|---|
http://www.gulftech.org/?node=research&article_id=00127-08252008 | patch exploit |
http://www.securityfocus.com/archive/1/495729/100/0/threaded | mailing list |
https://exchange.xforce.ibmcloud.com/vulnerabilities/44745 | vdb entry |
http://securityreason.com/securityalert/4192 | third party advisory |