Vulnerabilities > CVE-2006-4615 - Information Disclosure vulnerability in Shape Services Im+ Mobile Instant Messenger 3.10Forpocketpc

047910
CVSS 4.9 - MEDIUM
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
NONE
Availability impact
NONE
local
low complexity
shape-services

Summary

Shape Services IM+ Mobile Instant Messenger for Pocket PC 3.10 stores usernames and passwords in plaintext in %PROGRAMFILES%\IMPlus\implus.cfg, which allows local users to obtain sensitive information by reading the file.

Vulnerable Configurations

Part Description Count
Application
Shape_Services
1