Vulnerabilities > CVE-2005-1606 - Unspecified vulnerability in Positive Software H-Sphere Winbox 2.4.2Patch4/2.4.3Rc1

047910
CVSS 4.6 - MEDIUM
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
local
low complexity
positive-software

Summary

H-Sphere Winbox 2.4.2 and 2.4.3 RC1 stores sensitive information such as username and password in plaintext in world-readable log files, which allows local users to gain privileges.