CVE-2014-9575
08.01.2015, 15:59
VDG Security SENSE (formerly DIVA) before 2.3.15 allows remote attackers to bypass authentication, and consequently read and modify arbitrary plugin settings, via an encoded : (colon) character in the Authorization HTTP header.Enginsight
Vendor | Product | Version |
---|---|---|
vdgsecurity | vdg_sense | 𝑥 ≤ 2.3.14 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References