Required CVE Record Information
Description
AirDroid 1.0.4 beta implements authentication through direct transmission of a password hash over HTTP, which makes it easier for remote attackers to obtain access by sniffing the local wireless network and then replaying the authentication data.
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 2 Total
- archives.neohapsis.com: 20120712 security advisory: AirDroid 1.0.4 beta mailing-listx_transferred
- http://www.tele-consulting.com/advisories/TC-SA-2012-02.txt x_transferred