vendor:
DelphiTurk e-Posta
by:
Kozan
5.5
CVSS
MEDIUM
Disclosure of passwords to local users
200
CWE
Product Name: DelphiTurk e-Posta
Affected Version From: DelphiTurk e-Posta v1.0
Affected Version To: DelphiTurk e-Posta v1.0
Patch Exists: NO
Related CWE:
CPE: a:delphiturk:delphiturk_e-posta:1.0
Platforms Tested: Windows
DelphiTurk e-Posta v1.0 Local Exploit
This exploit demonstrates how DelphiTurk e-Posta v1.0 discloses passwords to local users. It reads the passwords from the 'Profiles.adt' file located in the 'Delphi TurkDelphi Türk e-Posta 1.0Settings' directory.
Mitigation:
The vendor should update the application to securely store passwords and ensure that they are not accessible to unauthorized users.