7.5

CVE-2007-5778

Mobile Spy (1) stores login credentials in cleartext under the RetinaxStudios registry key, and (2) sends login credentials and log data over a cleartext HTTP connection, which allows attackers to obtain sensitive information by reading the registry or sniffing the network.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
FlexispyMobile Spy Version-
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.19% 0.639
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvd@nist.gov 6.4 10 4.9
AV:N/AC:L/Au:N/C:P/I:N/A:P
CWE-312 Cleartext Storage of Sensitive Information

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

http://osvdb.org/43625
Broken Link
http://osvdb.org/43626
Broken Link
http://securityreason.com/securityalert/3333
Broken Link
http://www.airscanner.com/security/07101401_mobilespy.htm
Broken Link
http://www.informit.com/articles/article.aspx?p=1077909
Third Party Advisory
http://www.securityfocus.com/archive/1/482663/100/0/threaded
Third Party Advisory
Broken Link
VDB Entry
http://www.securityfocus.com/bid/26177
Third Party Advisory
Broken Link
VDB Entry