4.6
CVSSv2

CVE-2002-2162

Published: 31/12/2002 Updated: 05/09/2008
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
VMScore: 465
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Cerulean Studios Trillian 0.73 and previous versions use weak encrypttion (XOR) for storing user passwords in .ini files in the Trillian directory, which allows local users to gain access to other user accounts.

Vulnerable Product Search on Vulmon Subscribe to Product

cerulean studios trillian 0.6351

cerulean studios trillian 0.725

cerulean studios trillian 0.73

Exploits

source: wwwsecurityfocuscom/bid/5677/info The Trillian instant messaging client uses weak encryption to store saved authentication credentials for instant messaging services The credentials are encrypted by using XOR with a static key that is used with every installation of the software Local attackers may potentially exploit this weak ...