vendor:
PassWd 1.2
by:
Daniel Roethlisberger
2.6
CVSS
LOW
Weak Encoding Algorithm
327
CWE
Product Name: PassWd 1.2
Affected Version From: PassWd 1.2
Affected Version To: PassWd 1.2
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2000
PassWd 1.2 Password Management Utility Weak Encoding Algorithm Vulnerability
PassWd 1.2 is a password management utility designed to store user login information to various URLs. The login information, which includes username, password and link location is stored in the pass.dat file which resides in the PassWD directory. The information is encrypted with a weak encoding algorithm and includes the key which can be used to decode any stored password. Decoder for PassWD v1.2 `pass.dat' password files was written by Daniel Roethlisberger in 2000 which can be used to decode the stored passwords.
Mitigation:
Upgrade to the latest version of PassWd 1.2 or use a different password management utility.