|
|
Info |
Last Modified |
| 6 months ago |
|
|
|
|
Description |
Commerce Server contains a flaw that may allow a malicious user to gain access to unauthorized privileges. The issue is triggered due to an error in the sample files within the "AuthFiles" directory which can be exploited to bypass authentication and logon as a valid user without knowing the password. This flaw may lead to a loss of integrity.
|
|
Classification |
Location:
Remote/Network Access Required
Attack Type:
Authentication Management
Impact:
Loss of Integrity
Exploit:
Exploit Available
Disclosure:
OSVDB Verified
OSVDB:
Web Related
|
|
Technical |
An attacker must supply a valid username in order to exploit this vulnerability.
|
|
Solution |
Currently, there are no known workarounds or upgrades to correct this issue. However, the vendor has released a patch to address this vulnerability.
|
|
Products |
|
Commerce Server
 |
2002 SP1 |
2002 |
|
|
|
|
|
|
Credit |
- Dimitri van de Giessen - d.vd.giessen
xs4all.nl -
|
|
BlogsProvided by Technorati
|
None found at this time
|
|
|