CNCVE编号:CNCVE-20020024 CVE编号: 安全级别:低 漏洞中文描述: Hotline Connect是种instant messaging应用软件,由Hotline Communications负责开发维护。据报告,Hotline Connect潜在地泄漏了身份验证信息。该软件在Bookmarks目录(program fileshotline communications ltd)中以明文方式保存用户登录名、口令。 漏洞英文描述: Hotline Connect is an instant messaging type application maintained by Hotline Communications. An issue has been reported in Hotline Connect which may potentially disclose authentication credentials to attackers. Hotline Connect stores account information in plaintext on the local system in the same directory Hotline Bookmarks are stored. 漏洞参考: http://archives.neohapsis.com/archives/bugtraq/2002-02/0338.html http://archives.neohapsis.com/archives/bugtraq/2002-02/0378.html http://www2.bigredh.com/hotline3/index.html 系统类型: Unix/Linux Win95/98/ME Win2000/NT 漏洞类型:设计错误