Flyspray Unspecified Security Bypass And Information Disclosure Vulnerabilities
BID:23214
Info
Flyspray Unspecified Security Bypass And Information Disclosure Vulnerabilities
| Bugtraq ID: | 23214 |
| Class: | Unknown |
| CVE: |
CVE-2007-1789 CVE-2007-1788 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 30 2007 12:00AM |
| Updated: | Jul 05 2016 10:20PM |
| Credit: | The vendor reported the information disclosure issue. Stefan Esser is credited with the discovery of this vulnerability. |
| Vulnerable: |
Flyspray Flyspray 0.9.9 |
| Not Vulnerable: |
Flyspray Flyspray 0.9.9.1 |
Discussion
Flyspray Unspecified Security Bypass And Information Disclosure Vulnerabilities
FlySpray is prone to a security-bypass vulnerability and an information-disclosure vulnerability.
An attacker can exploit these issues to gain administrative access to the affected application and to obtain sensitive information that may lead to further attacks.
This issue affects FlySpray 0.9.9; prior versions may also be affected.
FlySpray is prone to a security-bypass vulnerability and an information-disclosure vulnerability.
An attacker can exploit these issues to gain administrative access to the affected application and to obtain sensitive information that may lead to further attacks.
This issue affects FlySpray 0.9.9; prior versions may also be affected.
Exploit / POC
Flyspray Unspecified Security Bypass And Information Disclosure Vulnerabilities
Attackers can use a browser to exploit these issues.
Attackers can use a browser to exploit these issues.
Solution / Fix
Flyspray Unspecified Security Bypass And Information Disclosure Vulnerabilities
Solution:
The vendor released an update to address these issues. Please see the references for more information.
Solution:
The vendor released an update to address these issues. Please see the references for more information.
References
Flyspray Unspecified Security Bypass And Information Disclosure Vulnerabilities
References:
References:
- Flyspray Homepage (Flyspray )
- Flyspray Security Announcement 1 (Flyspray)
- Flyspray Changelog (Flyspray)