Логотип exploitDog
bind:CVE-2017-15999
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2017-15999

Количество 2

Количество 2

nvd логотип

CVE-2017-15999

больше 8 лет назад

In the "NQ Contacts Backup & Restore" application 1.1 for Android, no HTTPS is used for transmitting login and synced user data. When logging in, the username is transmitted in cleartext along with an SHA-1 hash of the password. The attacker can either crack this hash or use it for further attacks where only the hash value is required.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-vxjg-xmrq-x393

больше 3 лет назад

In the "NQ Contacts Backup & Restore" application 1.1 for Android, no HTTPS is used for transmitting login and synced user data. When logging in, the username is transmitted in cleartext along with an SHA-1 hash of the password. The attacker can either crack this hash or use it for further attacks where only the hash value is required.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2017-15999

In the "NQ Contacts Backup & Restore" application 1.1 for Android, no HTTPS is used for transmitting login and synced user data. When logging in, the username is transmitted in cleartext along with an SHA-1 hash of the password. The attacker can either crack this hash or use it for further attacks where only the hash value is required.

CVSS3: 9.8
0%
Низкий
больше 8 лет назад
github логотип
GHSA-vxjg-xmrq-x393

In the "NQ Contacts Backup & Restore" application 1.1 for Android, no HTTPS is used for transmitting login and synced user data. When logging in, the username is transmitted in cleartext along with an SHA-1 hash of the password. The attacker can either crack this hash or use it for further attacks where only the hash value is required.

CVSS3: 9.8
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу