First published: Fri Sep 30 2005(Updated: )
The "reset password" feature in Macromedia Breeze 5.0 stores passwords in plaintext in the database instead of the hash, which allows attackers with access to the database to obtain the passwords.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Macromedia Breeze | =5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-3112 is considered a high severity vulnerability due to the storage of plaintext passwords.
To fix CVE-2005-3112, implement a secure password hashing mechanism in the application and update your database schema.
The potential impacts of CVE-2005-3112 include unauthorized access to user accounts and exposure of sensitive information.
CVE-2005-3112 affects Macromedia Breeze version 5 only.
Attackers with access to the Macromedia Breeze 5.0 database can exploit CVE-2005-3112 to retrieve stored plaintext passwords.