漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Hardcoded Credentials
Vulnerability Description
The configuration file is encrypted with a static key derived from a static five-character password which allows an attacker to decrypt this file. The application hashes this five-character password with the outdated and broken MD5 algorithm (no salt) and uses the first five bytes as the key for RC4. The configuration file is then encrypted with these parameters.
CVSS Information
N/A
Vulnerability Type
使用硬编码的凭证
Vulnerability Title
Faronics WINSelect 安全漏洞
Vulnerability Description
Faronics WINSelect是Faronics公司的一款应用程序。用于自定义 Windows 电脑的使用配置。 Faronics WINSelect 8.30.xx.903 版本之前存在安全漏洞,该漏洞源于配置文件使用由静态五个字符密码派生的静态密钥加密。
CVSS Information
N/A
Vulnerability Type
N/A