Vulnerabilities > CVE-2005-0823 - Local Credential Storage vulnerability in Thepoolclub Ipool and Isnooker

047910
CVSS 4.6 - MEDIUM
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
local
low complexity
thepoolclub
exploit available

Summary

ThePoolClub (1) iPool and (2) iSnooker 1.6.81 and earlier stores usernames and passwords in cleartext in the MyDetails.txt file, which allows local users to gain privileges.

Vulnerable Configurations

Part Description Count
Application
Thepoolclub
2

Exploit-Db

  • descriptioniPool <= 1.6.81 Local Password Disclosure Exploit. CVE-2005-0823. Local exploit for windows platform
    idEDB-ID:885
    last seen2016-01-31
    modified2005-03-16
    published2005-03-16
    reporterKozan
    sourcehttps://www.exploit-db.com/download/885/
    titleiPool <= 1.6.81 - Local Password Disclosure Exploit
  • descriptioniSnooker <= 1.6.8 Local Password Disclosure Exploit. CVE-2005-0823. Local exploit for windows platform
    idEDB-ID:884
    last seen2016-01-31
    modified2005-03-16
    published2005-03-16
    reporterKozan
    sourcehttps://www.exploit-db.com/download/884/
    titleiSnooker <= 1.6.8 - Local Password Disclosure Exploit