CVE-2014-9575
08.01.2015, 15:59
VDG Security SENSE (formerly DIVA) before 2.3.15 allows remote attackers to bypass authentication, and consequently read and modify arbitrary plugin settings, via an encoded : (colon) character in the Authorization HTTP header.Enginsight
| Vendor | Product | Version |
|---|---|---|
| vdgsecurity | vdg_sense | 𝑥 ≤ 2.3.14 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References