PT-2006-1910 · Global Hauri · Virobot

Publicado

2006-02-23

·

Atualizado

2018-10-18

·

CVE-2006-0864

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Global Hauri ViRobot version 2.0 20050817
Description The issue allows remote attackers to gain administrative privileges by providing an arbitrary cookie value, as the filescan component does not verify the Cookie HTTP header.
Recommendations For Global Hauri ViRobot version 2.0 20050817, consider restricting access to the filescan component until a fix is available, and avoid using arbitrary cookie values in the Cookie HTTP header. At the moment, there is no information about a newer version that contains a fix for this issue.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-0864

Produtos afetados

Virobot