PureVPN CVE-2018-18656 Local Information Disclosure Vulnerability
BID:105997
Info
PureVPN CVE-2018-18656 Local Information Disclosure Vulnerability
| Bugtraq ID: | 105997 |
| Class: | Input Validation Error |
| CVE: |
CVE-2018-18656 |
| Remote: | No |
| Local: | Yes |
| Published: | Oct 26 2018 12:00AM |
| Updated: | Oct 26 2018 12:00AM |
| Credit: | Manuel Nader of Trustwave |
| Vulnerable: |
PureVPN PureVPN 5.18.2.0 |
| Not Vulnerable: |
PureVPN PureVPN 6.1 |
Discussion
PureVPN CVE-2018-18656 Local Information Disclosure Vulnerability
PureVPN is prone to local information-disclosure vulnerability.
An attacker can exploit this issue to obtain sensitive information that may aid in further attacks.
Versions prior to PureVPN client 6.1.0 are vulnerable.
PureVPN is prone to local information-disclosure vulnerability.
An attacker can exploit this issue to obtain sensitive information that may aid in further attacks.
Versions prior to PureVPN client 6.1.0 are vulnerable.
Exploit / POC
PureVPN CVE-2018-18656 Local Information Disclosure Vulnerability
The researcher has created a proof-of-concept to demonstrate the issue. Please see the references for more information.
The researcher has created a proof-of-concept to demonstrate the issue. Please see the references for more information.
Solution / Fix
PureVPN CVE-2018-18656 Local Information Disclosure Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.