VDG Security SENSE (formerly DIVA) before 2.3.15 allows remote attackers to bypass authentication, and consequently read and modify arbitrary plugin settings, via an encoded : (colon) character in the Authorization HTTP header.
References
Configurations
Information
Published : 2015-01-08 07:59
Updated : 2015-01-08 11:43
NVD link : CVE-2014-9575
Mitre link : CVE-2014-9575
JSON object : View
CWE
CWE-264
Permissions, Privileges, and Access Controls
Products Affected
vdgsecurity
- vdg_sense