PT-2012-5538 · Psyced · Psyced
Publicado
2012-08-25
·
Atualizado
2012-08-27
·
CVE-2012-4671
CVSS v2.0
5.8
Média
| Vetor | AV:N/AC:M/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
psyced versions prior to 20120821
Description
The issue allows remote XMPP servers to spoof domains via responses for domains that were not asserted, due to a lack of verification that a request was made for an XMPP Server Dialback response.
Recommendations
For versions prior to 20120821, update to a version that includes the fix for this issue to prevent domain spoofing.
Correção
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Psyced