Lasso Professional Server Remote Authentication Bypass Vulnerability
BID:14543
Info
Lasso Professional Server Remote Authentication Bypass Vulnerability
| Bugtraq ID: | 14543 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 10 2005 12:00AM |
| Updated: | Aug 10 2005 12:00AM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
OmniPilot Software Lasso Professional Server 8.0.5 OmniPilot Software Lasso Professional Server 8.0.4 |
| Not Vulnerable: | |
Discussion
Lasso Professional Server Remote Authentication Bypass Vulnerability
Lasso Professional Server is susceptible to a remote authentication bypass vulnerability. This issue is due to a failure of the application to properly enforce defined security constraints.
This vulnerability allows remote attackers to gain access to potentially sensitive information contained in Web pages they would normally be unable to see, potentially aiding them in further attacks. Depending on the contents and design of the targeted Web pages, attackers may possibly interact with the Web site to cause data alterations or destruction.
This issue is present in versions 8.0.4 and 8.0.5 of Lasso Professional Server.
Lasso Professional Server is susceptible to a remote authentication bypass vulnerability. This issue is due to a failure of the application to properly enforce defined security constraints.
This vulnerability allows remote attackers to gain access to potentially sensitive information contained in Web pages they would normally be unable to see, potentially aiding them in further attacks. Depending on the contents and design of the targeted Web pages, attackers may possibly interact with the Web site to cause data alterations or destruction.
This issue is present in versions 8.0.4 and 8.0.5 of Lasso Professional Server.
Exploit / POC
Lasso Professional Server Remote Authentication Bypass Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
Lasso Professional Server Remote Authentication Bypass Vulnerability
Solution:
The vendor has released a fix to address this issue:
OmniPilot Software Lasso Professional Server 8.0.4
OmniPilot Software Lasso Professional Server 8.0.5
Solution:
The vendor has released a fix to address this issue:
OmniPilot Software Lasso Professional Server 8.0.4
-
OmniPilot Software Security Fix 804-805.zip
http://support.omnipilot.com/article_files/Security%20Fix%20804-805.zi p
OmniPilot Software Lasso Professional Server 8.0.5
-
OmniPilot Software Security Fix 804-805.zip
http://support.omnipilot.com/article_files/Security%20Fix%20804-805.zi p
References
Lasso Professional Server Remote Authentication Bypass Vulnerability
References:
References:
- Lasso Professional Server Home Page (OmniPilot Software)
- Security Fix for 8.0.4 and 8.0.5 (OmniPilot Software)