Vulnerabilities > CVE-2002-0486 - Weak Password Encryption vulnerability in Workforceroi Xpede 4.1/7.0

047910
CVSS 7.2 - HIGH
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
local
low complexity
workforceroi
exploit available

Summary

Intellisol Xpede 4.1 uses weak encryption to store authentication information in cookies, which could allow local users with access to the cookies to gain privileges.

Vulnerable Configurations

Part Description Count
Application
Workforceroi
2

Exploit-Db

descriptionWorkforceROI Xpede 4.1/7.0 Weak Password Encryption Vulnerability. CVE-2002-0486. Local exploit for windows platform
idEDB-ID:21351
last seen2016-02-02
modified2002-03-22
published2002-03-22
reporterc3rb3r
sourcehttps://www.exploit-db.com/download/21351/
titleWorkforceROI Xpede 4.1/7.0 Weak Password Encryption Vulnerability