Vulnerabilities > CVE-2002-0933 - Authentication Credentials vulnerability in Datalex Bookit! Consumer Plaintext

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
datalex

Summary

Datalex PLC BookIt! Consumer before 2.2 stores usernames and passwords in plaintext in a cookie, which could allow remote attackers to gain privileges via Cross-site scripting or sniffing attacks.

Vulnerable Configurations

Part Description Count
Application
Datalex
1