CVE
- Id
- 49421
- CVE No.
- CVE-2011-1509
- Status
- Candidate
- Description
- The encryptPassword function in Login.js in ManageEngine ServiceDesk Plus (SDP) 8012 and earlier uses a Caesar cipher for encryption of passwords in cookies, which makes it easier for remote attackers to obtain sensitive information by sniffing the network.
- Phase
- Assigned (20110323)
- Votes
- None (candidate not yet proposed)
- Comments