CVE-2014-9575 Information
Feb 14, 2021
cve
Description
VDG Security SENSE (formerly DIVA) before 2.3.15 allows remote attackers to bypass authentication and consequently read and modify arbitrary plugin settings via an encoded : (colon) character in the Authorization HTTP header.
Reference
http://packetstormsecurity.com/files/129656/VDG-Security-SENSE-2.3.13-File-Disclosure-Bypass-Buffer-Overflow.html http://seclists.org/fulldisclosure/2014/Dec/76 https://vdgsecurity.com/downloads/software/?file=1.+DIVA+2.32F2.+Changelog+2.3.16.txt https://www.sec-consult.com/fxdata/seccons/prod/temedia/advisories_txt/20141218-0_VDG_Security_SENSE_Multiple_critical_vulnerabilities_v10.txt
Share on: