6.8 Medium
AI Score
Confidence
Low
0.005 Low
EPSS
Percentile
77.0%
The Xelex MobileTrack application 2.3.7 and earlier for Android uses hardcoded credentials, which allows remote attackers to obtain sensitive information via an unencrypted (1) FTP or (2) HTTP session.
blog.mobiledefense.com/2012/05/mobile-defense-finds-two-security-vulnerabilities-in-xelex-mobiletrack/
secunia.com/advisories/49268
www.kb.cert.org/vuls/id/464683
www.securityfocus.com/bid/53634
exchange.xforce.ibmcloud.com/vulnerabilities/75783