Vulnerabilities > CVE-2010-0616 - Credentials Management vulnerability in Myshell Evalsmsi 2.1.03

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
myshell
CWE-255

Summary

evalSMSI 2.1.03 stores passwords in cleartext in the database, which allows attackers with database access to gain privileges. NOTE: remote attack vectors are possible by leveraging a separate SQL injection vulnerability.

Vulnerable Configurations

Part Description Count
Application
Myshell
1

Common Weakness Enumeration (CWE)