login_screen.tcl in aMSN (aka Alvaro's Messenger) before 0.97.1 saves a password after logout, which allows physically proximate attackers to hijack a session by visiting an unattended workstation.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 00:58
Type | Values Removed | Values Added |
---|---|---|
References | () http://amsn.svn.sourceforge.net/viewvc/amsn/trunk/amsn/login_screen.tcl?r1=9960&r2=10259&pathrev=10259 - | |
References | () http://sourceforge.net/project/shownotes.php?release_id=610067 - | |
References | () http://www.amsn-project.net/forums/index.php?topic=5317.0 - |
Information
Published : 2010-04-20 16:30
Updated : 2024-11-21 00:58
NVD link : CVE-2008-7255
Mitre link : CVE-2008-7255
CVE.ORG link : CVE-2008-7255
JSON object : View
Products Affected
amsn
- amsn
CWE
CWE-255
Credentials Management Errors