CVE-2006-4745
Last modified
CVE-2006-4745 is a vulnerability of currently unknown severity. ScaryBear PocketExpense Pro 3.9.1 uses an internally recorded key to protect a data file whose contents are stored in plaintext, which allows local users to disable authentication and access the file by modifying a certain value in the file header.. EPSS estimates a 0.42% chance of exploitation in the next 30 days.
Description
ScaryBear PocketExpense Pro 3.9.1 uses an internally recorded key to protect a data file whose contents are stored in plaintext, which allows local users to disable authentication and access the file by modifying a certain value in the file header.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Scarybear | Pocketexpense Pro | 3.9.1 |
References
- http://airscanner.com/security/06062602_pocketexpensepro.htmExploit, Vendor Advisory
- http://airscanner.com/security/06062602_pocketexpensepro.htmExploit, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2006-4745?
How severe is CVE-2006-4745?
How do I fix CVE-2006-4745?
Are you affected by CVE-2006-4745?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
