PT-2007-5206 · Secure Computing · Secure Computing Securityreporter

Oliver Karow

·

Published

2007-07-25

·

Updated

2017-07-29

·

CVE-2007-3986

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Secure Computing SecurityReporter (aka Network Security Analyzer) version 4.6.3
Description: The issue allows remote attackers to bypass authentication. This is achieved by specifying the eventcache directory and a non-GIF file through a name parameter, which causes the $dontvalidate variable to be set to true.
Recommendations: For Secure Computing SecurityReporter (aka Network Security Analyzer) version 4.6.3, consider restricting access to the file.cgi to minimize the risk of exploitation until a patch is available. Avoid using the name parameter in the affected endpoint to prevent authentication bypass.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-3986

Affected Products

Secure Computing Securityreporter