CVE-2008-7255

Severity CVSS v4.0:
Pending analysis
Type:
CWE-255 Credentials Management
Publication date:
20/04/2010
Last modified:
11/04/2025

Description

login_screen.tcl in aMSN (aka Alvaro's Messenger) before 0.97.1 saves a password after logout, which allows physically proximate attackers to hijack a session by visiting an unattended workstation.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:amsn:amsn:*:*:*:*:*:*:*:* 0.97 (including)
cpe:2.3:a:amsn:amsn:0.83:*:*:*:*:*:*:*
cpe:2.3:a:amsn:amsn:0.90:*:*:*:*:*:*:*
cpe:2.3:a:amsn:amsn:0.91:*:*:*:*:*:*:*
cpe:2.3:a:amsn:amsn:0.92:*:*:*:*:*:*:*
cpe:2.3:a:amsn:amsn:0.93:*:*:*:*:*:*:*
cpe:2.3:a:amsn:amsn:0.94:*:*:*:*:*:*:*
cpe:2.3:a:amsn:amsn:0.95:*:*:*:*:*:*:*
cpe:2.3:a:amsn:amsn:0.96:*:*:*:*:*:*:*