Comvigo IM Lock 2006 uses a simple substitution cipher to encrypt a password stored in the msnvs\prc registry value, for which all users have Read permission, which allows local users to bypass the product's blocking functionality by decrypting the password.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 00:08
Type | Values Removed | Values Added |
---|---|---|
References | () http://secunia.com/advisories/19140 - Vendor Advisory | |
References | () http://www.securityfocus.com/archive/1/426935/100/0/threaded - | |
References | () http://www.securityfocus.com/bid/16988 - | |
References | () http://www.vupen.com/english/advisories/2006/0866 - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/25219 - |
Information
Published : 2006-03-14 01:06
Updated : 2024-11-21 00:08
NVD link : CVE-2006-1198
Mitre link : CVE-2006-1198
CVE.ORG link : CVE-2006-1198
JSON object : View
Products Affected
comvigo
- im_lock
CWE