Vulnerabilities > CVE-2010-0616 - Credentials Management vulnerability in Myshell Evalsmsi 2.1.03

047910
CVSS 0.0 - NONE
Attack vector
UNKNOWN
Attack complexity
UNKNOWN
Privileges required
UNKNOWN
Confidentiality impact
UNKNOWN
Integrity impact
UNKNOWN
Availability impact
UNKNOWN

Summary

evalSMSI 2.1.03 stores passwords in cleartext in the database, which allows attackers with database access to gain privileges. NOTE: remote attack vectors are possible by leveraging a separate SQL injection vulnerability.

Vulnerable Configurations

Part Description Count
Application
Myshell
1

Common Weakness Enumeration (CWE)