CVE-2009-2344
07.07.2009, 19:30
The web-based management interfaces in Sourcefire Defense Center (DC) and 3D Sensor before 4.8.2 allow remote authenticated users to gain privileges via a $admin value for the admin parameter in an edit action to admin/user/user.cgi and unspecified other components.Enginsight
Vendor | Product | Version |
---|---|---|
sourcefire | 3d_sensor | 𝑥 ≤ 4.8.1 |
sourcefire | 3d_sensor | 4.8 |
sourcefire | 3d_sensor | 4.8.0.3 |
sourcefire | 3d_sensor | 4.8.0.4 |
sourcefire | defense_center | 𝑥 ≤ 4.8.1 |
sourcefire | defense_center | 4.8 |
sourcefire | defense_center | 4.8.0.3 |
sourcefire | defense_center | 4.8.0.4 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References