CVE-2008-1106
09.06.2008, 23:32
The management interface in Akamai Client (formerly Red Swoosh) 3322 and earlier allows remote attackers to bypass authentication via an HTTP request that contains (1) no Referer header, or (2) a spoofed Referer header that matches an approved domain, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks and force the client to download and execute arbitrary files.Enginsight
Vendor | Product | Version |
---|---|---|
akamai_technologies | client | 𝑥 ≤ 3322 |
red_swoosh | client | 𝑥 ≤ 3322 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References