vendor:
iPool
by:
Kozan
5.5
CVSS
MEDIUM
Local Password Disclosure
200
CWE
Product Name: iPool
Affected Version From: 1.6.81
Affected Version To: 1.6.81
Patch Exists: NO
Related CWE:
CPE: a:memir_software:ipool:1.6.81
Platforms Tested: Windows
iPool <= v1.6.81 Local Password Disclosure Exploit
iPool 1.6.81 discloses passwords to local users. The exploit allows an attacker to retrieve passwords stored in the MyDetails.txt file.
Mitigation:
Update to a patched version of iPool that does not have this vulnerability. Ensure that the MyDetails.txt file is properly protected and only accessible by authorized users.