Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3xcj-74x5-w6qm

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Kiwi CatTools before 3.2.0 beta uses weak encryption ("reversible encoding") for passwords, account names, and IP addresses in kiwidb-cattools.kdb, which might allow local users to gain sensitive information by decrypting the file. NOTE: this issue could be leveraged with a directory traversal vulnerability for a remote attack vector.

Kiwi CatTools before 3.2.0 beta uses weak encryption ("reversible encoding") for passwords, account names, and IP addresses in kiwidb-cattools.kdb, which might allow local users to gain sensitive information by decrypting the file. NOTE: this issue could be leveraged with a directory traversal vulnerability for a remote attack vector.

EPSS

Процентиль: 19%
0.00061
Низкий

Связанные уязвимости

nvd
почти 19 лет назад

Kiwi CatTools before 3.2.0 beta uses weak encryption ("reversible encoding") for passwords, account names, and IP addresses in kiwidb-cattools.kdb, which might allow local users to gain sensitive information by decrypting the file. NOTE: this issue could be leveraged with a directory traversal vulnerability for a remote attack vector.

EPSS

Процентиль: 19%
0.00061
Низкий