Required CVE Record Information
Description
Krusader 1.50-beta1 up to 1.70.0 stores passwords for remote connections in cleartext in the bookmark file (krbookmarks.xml), which allows attackers to steal passwords by obtaining the file.
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 4 Total
- securityfocus.com: 19194 vdb-entryx_transferred
- http://groups.google.com/group/krusader-news/browse_thread/thread/ec719041ed4a1a14 x_transferred
- vupen.com: ADV-2006-2992 vdb-entryx_transferred
- http://krusader.sourceforge.net/phpBB/viewtopic.php?p=7965 x_transferred