PT-2006-1910 · Global Hauri · Virobot

Published

2006-02-23

·

Updated

2018-10-18

·

CVE-2006-0864

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Global Hauri ViRobot version 2.0 20050817
Description The issue allows remote attackers to gain administrative privileges by providing an arbitrary cookie value, as the filescan component does not verify the Cookie HTTP header.
Recommendations For Global Hauri ViRobot version 2.0 20050817, consider restricting access to the filescan component until a fix is available, and avoid using arbitrary cookie values in the Cookie HTTP header. At the moment, there is no information about a newer version that contains a fix for this issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-0864

Affected Products

Virobot