Vulnerability Description
hotfoon4.exe in Hotfoon 4.00 stores user names and passwords in cleartext in the hotfoon2 registry key, which allows local users to gain access to user accounts and steal phone service.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Hotfoon Corporation | Hotfoon | 4.0 |
Related Weaknesses (CWE)
References
- http://archives.neohapsis.com/archives/bugtraq/2002-11/0115.htmlExploit
- http://www.iss.net/security_center/static/10591.php
- http://www.securityfocus.com/bid/6155
- http://archives.neohapsis.com/archives/bugtraq/2002-11/0115.htmlExploit
- http://www.iss.net/security_center/static/10591.php
- http://www.securityfocus.com/bid/6155
FAQ
What is CVE-2002-2384?
CVE-2002-2384 is a vulnerability with a CVSS score of 3.6 (LOW). hotfoon4.exe in Hotfoon 4.00 stores user names and passwords in cleartext in the hotfoon2 registry key, which allows local users to gain access to user accounts and steal phone service.
How severe is CVE-2002-2384?
CVE-2002-2384 has been rated LOW with a CVSS base score of 3.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2002-2384?
Check the references section above for vendor advisories and patch information. Affected products include: Hotfoon Corporation Hotfoon.