Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2002-0324


Vulnerability Score 7.5 7.5
CVE Id CVE-2002-0324
Last Modified 10 Sep 2008 08:00:56
Published 25 Jun 2002 12:00:00
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact PARTIAL PARTIAL
Availability Impact PARTIAL PARTIAL
Access Vector NETWORK
Access Complexity LOW
Authentication NONE



Greymatter 1.21c and earlier with the Bookmarklet feature enabled allows remote attackers to read a cleartext password and gain administrative privileges by guessing the name of a gmrightclick-*.reg file which contains the administrator name and password in cleartext, then retrieving the file from the web server before the Greymatter administrator performs a "Clear And Exit" action.

Vulnerable Systems


  • Noah Gray Graymatter 1.1

  • Noah Gray Graymatter 1.1b

  • Noah Gray Graymatter 1.21

  • Noah Gray Graymatter 1.2b


XF - greymatter-gmrightclick-account-information(8277)


BUGTRAQ - 20020224 Greymatter 1.21c and earlier - remote login/pass exposure

BID - 4169

Last Updated: 27 May 2016 10:36:52