Citrix Program Neighborhood client before 9.150 caches the user password in plaintext in the GUI while asterisks are used to visually obfuscate the password, which allows attackers with access to the session to obtain the password by using a tool to directly access the field.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2005-12-20T11:00:00Z

Updated: 2024-09-16T20:17:06.914Z

Reserved: 2005-12-20T00:00:00Z

Link: CVE-2005-4412

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2005-12-20T11:03:00.000

Modified: 2008-09-05T20:56:49.347

Link: CVE-2005-4412

cve-icon Redhat

No data.