Citrix Program Neighborhood client before 9.150 caches the user password in plaintext in the GUI while asterisks are used to visually obfuscate the password, which allows attackers with access to the session to obtain the password by using a tool to directly access the field.
References
Link | Resource |
---|---|
http://securitytracker.com/id?1015372 | Exploit |
http://support.citrix.com/article/CTX108108 | Exploit Vendor Advisory |
http://securitytracker.com/id?1015372 | Exploit |
http://support.citrix.com/article/CTX108108 | Exploit Vendor Advisory |
Configurations
History
21 Nov 2024, 00:04
Type | Values Removed | Values Added |
---|---|---|
References | () http://securitytracker.com/id?1015372 - Exploit | |
References | () http://support.citrix.com/article/CTX108108 - Exploit, Vendor Advisory |
Information
Published : 2005-12-20 11:03
Updated : 2024-11-21 00:04
NVD link : CVE-2005-4412
Mitre link : CVE-2005-4412
CVE.ORG link : CVE-2005-4412
JSON object : View
Products Affected
citrix
- program_neighborhood_client
CWE