vendor:
Emesene
by:
Daniel Godoy
5.5
CVSS
MEDIUM
Password Disclosure
200
CWE
Product Name: Emesene
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Linux
2012
Emesene Password Disclosure
This exploit allows an attacker to disclose passwords in Emesene, a software used for instant messaging. The script reads a file called 'users.dat' located in the '.config/emesene1.0' directory and prints out the email and corresponding password in clear text. This vulnerability can be exploited if the user has enabled the 'remember password' feature.
Mitigation:
To mitigate this vulnerability, users should disable the 'remember password' feature in Emesene. Additionally, users should consider using a strong and unique password for their Emesene account.