CVE-2018-7259
9.8
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD
Description
The FSX / P3Dv4 installer 2.0.1.231 for Flight Sim Labs A320-X sends a user's Google account credentials to http://installLog.flightsimlabs.com/LogHandler3.ashx if a pirated serial number has been entered, which allows remote attackers to obtain sensitive information, e.g., by sniffing the network for cleartext HTTP traffic. This behavior was removed in 2.0.1.232.
Affected (1)
Products: Flightsimlabs: A320 X
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 2.0.1.231 |
References (6)
Source: cve@mitre.org
Issue Tracking
Source: cve@mitre.org
Source: cve@mitre.org
Issue TrackingPress/Media Coverage
Source: af854a3a-2127-422b-91ae-364da2661108
Issue Tracking
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingPress/Media Coverage
Timeline
No history available yet.