3.6

CVE-2006-4745

Exploit
ScaryBear PocketExpense Pro 3.9.1 uses an internally recorded key to protect a data file whose contents are stored in plaintext, which allows local users to disable authentication and access the file by modifying a certain value in the file header.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Scarybear ≫ Pocketexpense Pro Version 3.9.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.43% 0.358
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 3.6 3.9 4.9
AV:L/AC:L/Au:N/C:P/I:P/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://airscanner.com/security/06062602_pocketexpensepro.htm
Vendor Advisory
Exploit
http://securityreason.com/securityalert/1559
http://www.securityfocus.com/archive/1/445607/100/0/threaded