CVE-2005-1097 describes a local password disclosure vulnerability in Rebrand P2P Share Spy version 2.2. The software stores user passwords in plaintext within the Windows registry, specifically in the txtPassword value. This allows any local user with access to the system to easily retrieve sensitive credentials, potentially leading to privilege escalation or unauthorized access to other resources. The vulnerability has a CVSS score of 4.6, indicating a medium severity. It requires local access (AV:L) and has low attack complexity (AC:L), meaning it's relatively easy to exploit once local access is gained. The potential impact includes confidentiality, integrity, and availability compromises (C:P/I:P/A:P). While there is no evidence of active exploitation (KEV: No, Hot List: Inactive), a proof-of-concept exploit (EDB-920) is publicly available on ExploitDB. Despite this, the vulnerability has received minimal community discussion and media coverage, suggesting it is not widely known or targeted.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.2CPE matchmatch criteria | cpe:2.3:a:rebrand:p2p_share_spy:2.2:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:P/I:P/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.