Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

WorkforceROI Xpede Weak Password Encryption Vulnerability

An issue has been reported in Xpede, which could lead to a compromise of user authentication information.

Reportedly, Xpede cookies containing username and password data is stored using a weak encryption method. Therefore if a user obtains access to cookies reisding on a system, he/she may be able to reveal authentication information of Xpede users.







 

Privacy Statement
Copyright 2008, SecurityFocus