PT-2010-1467 · Xerver · Xerver

Dr_Ide

·

Publicado

2010-03-03

·

Atualizado

2017-09-19

·

CVE-2009-4657

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Xerver version 4.32
Description The issue concerns a lack of authentication in the administrator package, allowing remote attackers to modify application settings. This can be achieved by connecting to the application on port 32123. For example, an attacker can set the action option to wizardStep1 to exploit this issue.
Recommendations For Xerver version 4.32, consider restricting access to port 32123 until a fix is available. As a temporary workaround, implement additional authentication mechanisms for the administrator package to prevent unauthorized access.

Exploit

Correção

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2009-4657

Produtos afetados

Xerver