Pathways Homecare 6.5 uses weak encryption for user names and passwords, which allows local users to gain privileges by recovering the passwords from the pwhc.ini file.
References
Link | Resource |
---|---|
http://www.iss.net/security_center/static/7682.php | Broken Link |
http://www.securityfocus.com/archive/1/244367 | Broken Link Third Party Advisory VDB Entry |
http://www.securityfocus.com/bid/3653 | Broken Link Exploit Third Party Advisory VDB Entry |
http://www.iss.net/security_center/static/7682.php | Broken Link |
http://www.securityfocus.com/archive/1/244367 | Broken Link Third Party Advisory VDB Entry |
http://www.securityfocus.com/bid/3653 | Broken Link Exploit Third Party Advisory VDB Entry |
Configurations
History
20 Nov 2024, 23:37
Type | Values Removed | Values Added |
---|---|---|
References | () http://www.iss.net/security_center/static/7682.php - Broken Link | |
References | () http://www.securityfocus.com/archive/1/244367 - Broken Link, Third Party Advisory, VDB Entry | |
References | () http://www.securityfocus.com/bid/3653 - Broken Link, Exploit, Third Party Advisory, VDB Entry |
14 Feb 2024, 16:55
Type | Values Removed | Values Added |
---|---|---|
References | (BUGTRAQ) http://www.securityfocus.com/archive/1/244367 - Broken Link, Third Party Advisory, VDB Entry | |
References | (BID) http://www.securityfocus.com/bid/3653 - Broken Link, Exploit, Third Party Advisory, VDB Entry | |
References | (XF) http://www.iss.net/security_center/static/7682.php - Broken Link | |
CWE | CWE-326 | |
CVSS |
v2 : v3 : |
v2 : 4.6
v3 : 7.8 |
Information
Published : 2001-12-31 05:00
Updated : 2024-11-20 23:37
NVD link : CVE-2001-1546
Mitre link : CVE-2001-1546
CVE.ORG link : CVE-2001-1546
JSON object : View
Products Affected
mckesson
- pathways_homecare
CWE
CWE-326
Inadequate Encryption Strength