Vulnerability Description
Gyach Enhanced (Gyach-E) before 1.0.0 stores passwords in plaintext, which allows attackers to obtain user passwords by reading the configuration file.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Phrozensmoke | Gyach Enhanced | <= 1.0.0_pre |
Related Weaknesses (CWE)
References
- http://www.osvdb.org/8834
- http://www.phrozensmoke.com/projects/pyvoicechat/changelog.phpPatch
- http://www.osvdb.org/8834
- http://www.phrozensmoke.com/projects/pyvoicechat/changelog.phpPatch
FAQ
What is CVE-2004-2708?
CVE-2004-2708 is a vulnerability with a CVSS score of 5.0 (MEDIUM). Gyach Enhanced (Gyach-E) before 1.0.0 stores passwords in plaintext, which allows attackers to obtain user passwords by reading the configuration file.
How severe is CVE-2004-2708?
CVE-2004-2708 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2004-2708?
Check the references section above for vendor advisories and patch information. Affected products include: Phrozensmoke Gyach Enhanced.