PT-2010-1467 · Xerver · Xerver
Dr_Ide
·
Published
2010-03-03
·
Updated
2017-09-19
·
CVE-2009-4657
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Xerver version 4.32
Description
The issue concerns a lack of authentication in the administrator package, allowing remote attackers to modify application settings. This can be achieved by connecting to the application on port 32123. For example, an attacker can set the
action option to wizardStep1 to exploit this issue.Recommendations
For Xerver version 4.32, consider restricting access to port 32123 until a fix is available. As a temporary workaround, implement additional authentication mechanisms for the administrator package to prevent unauthorized access.
Exploit
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Xerver