PT-2010-1467 · Xerver · Xerver

Dr_Ide

·

Published

2010-03-03

·

Updated

2017-09-19

·

CVE-2009-4657

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Xerver version 4.32
Description The issue concerns a lack of authentication in the administrator package, allowing remote attackers to modify application settings. This can be achieved by connecting to the application on port 32123. For example, an attacker can set the action option to wizardStep1 to exploit this issue.
Recommendations For Xerver version 4.32, consider restricting access to port 32123 until a fix is available. As a temporary workaround, implement additional authentication mechanisms for the administrator package to prevent unauthorized access.

Exploit

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-4657

Affected Products

Xerver