VDG Security SENSE (formerly DIVA) before 2.3.15 allows remote attackers to bypass authentication, and consequently read and modify arbitrary plugin settings, via an encoded : (colon) character in the Authorization HTTP header.
References
Configurations
History
No history.
Information
Published : 2015-01-08 15:59
Updated : 2024-02-04 18:35
NVD link : CVE-2014-9575
Mitre link : CVE-2014-9575
CVE.ORG link : CVE-2014-9575
JSON object : View
Products Affected
vdgsecurity
- vdg_sense
CWE
CWE-264
Permissions, Privileges, and Access Controls