4.6
CVSSv2

CVE-2001-1003

Published: 31/08/2001 Updated: 18/10/2016
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
VMScore: 465
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Respondus 1.1.2 for WebCT uses weak encryption to remember usernames and passwords, which allows local users who can read the WEBCT.SVR file to decrypt the passwords and gain additional privileges.

Vulnerable Product Search on Vulmon Subscribe to Product

webct respondus 1.1.2

Exploits

source: wwwsecurityfocuscom/bid/3228/info Respondus is an application designed to add functionality to WebCT's quiz, self-test and survey tools WebCT is a commercial e-learning solution When a user opts to have Respondus remember the username/password for WebCT access, the information is saved encrypted in a file called 'WEBCTSRV' Th ...