Security Advisory

CVE-2006-7037

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2007-02-23 01:00:00
Last updated 2024-08-07 20:50:05
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

Mathcad 12 through 13.1 allows local users to bypass the security features by directly accessing or editing the XML representation of the worksheet with a text editor or other program, which allows attackers to (1) bypass password protection by replacing the password field with a hash of a known password, (2) modify timestamps to avoid detection of modifications, (3) remove locks by removing the "is-locked" attribute, and (4) view locked data, which is stored in plaintext.