CVE-2006-3816

Krusader 1.50-beta1 up to 1.70.0 stores passwords for remote connections in cleartext in the bookmark file (krbookmarks.xml), which allows attackers to steal passwords by obtaining the file.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:krusader:krusader:1.50_beta1:*:*:*:*:*:*:*
cpe:2.3:a:krusader:krusader:1.60.0:*:*:*:*:*:*:*
cpe:2.3:a:krusader:krusader:1.70.0:*:*:*:*:*:*:*
cpe:2.3:a:krusader:krusader:1.70.0_beta1:*:*:*:*:*:*:*

History

21 Nov 2024, 00:14

Type Values Removed Values Added
References () http://groups.google.com/group/krusader-news/browse_thread/thread/ec719041ed4a1a14 - Patch () http://groups.google.com/group/krusader-news/browse_thread/thread/ec719041ed4a1a14 - Patch
References () http://krusader.sourceforge.net/phpBB/viewtopic.php?p=7965 - Patch () http://krusader.sourceforge.net/phpBB/viewtopic.php?p=7965 - Patch
References () http://www.securityfocus.com/bid/19194 - () http://www.securityfocus.com/bid/19194 -
References () http://www.vupen.com/english/advisories/2006/2992 - () http://www.vupen.com/english/advisories/2006/2992 -

Information

Published : 2006-07-25 13:22

Updated : 2025-04-03 01:03


NVD link : CVE-2006-3816

Mitre link : CVE-2006-3816

CVE.ORG link : CVE-2006-3816


JSON object : View

Products Affected

krusader

  • krusader