Vulnerabilities > Coffeecup Software

DATE CVE VULNERABILITY TITLE RISK
2003-12-31 CVE-2003-1394 Credentials Management vulnerability in Coffeecup Software Coffeecup Password Wizard
CoffeeCup Software Password Wizard 4.0 stores sensitive information such as usernames and passwords in a .apw file under the web document root with insufficient access control, which allows remote attackers to obtain that information via a direct request for the file.
network
low complexity
coffeecup-software CWE-255
5.0
2001-02-12 CVE-2001-0103 Cryptographic Issues vulnerability in Coffeecup Software Coffeecup Direct FTP and Coffeecup Free FTP
CoffeeCup Direct and Free FTP clients uses weak encryption to store passwords in the FTPServers.ini file, which could allow attackers to easily decrypt the passwords.
local
low complexity
coffeecup-software CWE-310
4.6