Skip to main content

CVE-2005-2209

5.5
MEDIUMCVSS v3.1 Base Score
0.26%
LOW RiskEPSS (17th percentile)

Capturix ScanShare 1.06 build 50 stores sensitive information such as the password in cleartext in capturixss_cfg.ini, which is readable by local users.

Published: 7/11/2005
Modified: 6/16/2026
Back to CVE Lookup

Vulnerability Summary

CVSS v3 Score

5.5MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CVSS v2 Score

1.9

AV:L/AC:M/Au:N/C:P/I:N/A:N

EPSS Score (Exploitation Probability)

0.26%LOW Exploitation Risk
17th percentile

This vulnerability has a 0.26% probability of being exploited in the next 30 days, ranking higher than 17% of all scored CVEs.

CWE Classification

Related Vulnerabilities

Same Weakness Type(CWE-312)

CVE-2026-10786MEDIUM 6.5

Improper access control in the ticketing integration settings in Devolutions Server allows an authenticated low-privileged user to obtain cleartext credentials for configured ticketing integrations via a crafted API request. This issue affects : * Devolutions Server 2026.2.4.0 * Devolutions Server 2026.1.20.0 and earlier

6/8/2026
CVE-2025-34216CRITICAL 9.8

Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 22.0.1026 and Application prior to version 20.0.2702 (VA deployments only) expose a set of unauthenticated REST API endpoints that return configuration files and clear‑text passwords. The same endpoints also disclose the Laravel APP_KEY used for cryptographic signing. Because the APP_KEY is required to generate valid signed requests, an attacker who obtains it can craft malicious payloads that are accepted by the application and achieve remote code execution on the appliance. This vulnerability has been identified by the vendor as: V-2024-018 — RCE & Leaks via API.

9/29/2025
CVE-2025-34206CRITICAL 9.8

Vasion Print (formerly PrinterLogic) Virtual Appliance Host and Application (VA and SaaS deployments) mount host configuration and secret material under /var/www/efs_storage into many Docker containers with overly-permissive filesystem permissions. Files such as secrets.env, GPG-encrypted blobs in .secrets, MySQL client keys, and application session files are accessible from multiple containers. An attacker who controls or reaches any container can read or modify these artifacts, leading to credential theft, RCE via Laravel APP_KEY, Portainer takeover, and full compromise.

9/19/2025
CVE-2023-41095MEDIUM 6.8

Missing Encryption of Security Keys vulnerability in Silicon Labs OpenThread SDK on 32 bit, ARM (SecureVault High modules) allows potential modification or extraction of network credentials stored in flash. This issue affects Silicon Labs OpenThread SDK: 2.3.1 and earlier.

10/26/2023
CVE-2023-2809HIGH 7.8

Plaintext credential usage vulnerability in Sage 200 Spain 2023.38.001 version, the exploitation of which could allow a remote attacker to extract SQL database credentials from the DLL application. This vulnerability could be linked to known techniques to obtain remote execution of MS SQL commands and escalate privileges on Windows systems because the credentials are stored in plaintext.

10/4/2023

Similar SeverityMEDIUM