Greymatter 1.21c and earlier with the Bookmarklet feature enabled allows remote attackers to read a cleartext password and gain administrative privileges by guessing the name of a gmrightclick-*.reg file which contains the administrator name and password in cleartext, then retrieving the file from the web server before the Greymatter administrator performs a "Clear And Exit" action.
Metrics
Affected Vendors & Products
References
History
No history.

Status: PUBLISHED
Assigner: mitre
Published: 2002-05-03T04:00:00
Updated: 2024-08-08T02:42:29.184Z
Reserved: 2002-05-01T00:00:00
Link: CVE-2002-0324

No data.

Status : Deferred
Published: 2002-06-25T04:00:00.000
Modified: 2025-04-03T01:03:51.193
Link: CVE-2002-0324

No data.