mirror of
https://github.com/0xMarcio/cve.git
synced 2026-06-03 12:58:02 +02:00
18 lines
779 B
Markdown
18 lines
779 B
Markdown
### [CVE-2008-2747](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2747)
|
|

|
|

|
|

|
|
|
|
### Description
|
|
|
|
No-IP Dynamic Update Client (DUC) 2.2.1 on Windows uses weak permissions for the HKLM\SOFTWARE\Vitalwerks\DUC registry key, which allows local users to obtain obfuscated passwords and other sensitive information by reading the (1) TrayPassword, (2) Username, (3) Password, and (4) Hosts registry values.
|
|
|
|
### POC
|
|
|
|
#### Reference
|
|
- http://securityreason.com/securityalert/3952
|
|
|
|
#### Github
|
|
No PoCs found on GitHub currently.
|
|
|