Kaspersky Anti-Spam Unauthorized Directory Access Authentication Bypass Vulnerability
BID:24692
Info
Kaspersky Anti-Spam Unauthorized Directory Access Authentication Bypass Vulnerability
| Bugtraq ID: | 24692 |
| Class: | Design Error |
| CVE: |
CVE-2007-3502 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 28 2007 12:00AM |
| Updated: | May 07 2015 05:37PM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
Kaspersky Anti-Spam 3.0 MP1 |
| Not Vulnerable: | |
Discussion
Kaspersky Anti-Spam Unauthorized Directory Access Authentication Bypass Vulnerability
Kaspersky Anti-Spam is prone to an authentication-bypass vulnerability.
An attacker can exploit this issue to gain unauthorized access to certain directories of the web-based product configuration system. This may lead to other attacks.
Kaspersky Anti-Spam is prone to an authentication-bypass vulnerability.
An attacker can exploit this issue to gain unauthorized access to certain directories of the web-based product configuration system. This may lead to other attacks.
Exploit / POC
Kaspersky Anti-Spam Unauthorized Directory Access Authentication Bypass Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Kaspersky Anti-Spam Unauthorized Directory Access Authentication Bypass Vulnerability
Solution:
The vendor released an update to address this issue. Please see the references for more information.
Kaspersky Anti-Spam 3.0 MP1
Solution:
The vendor released an update to address this issue. Please see the references for more information.
Kaspersky Anti-Spam 3.0 MP1
-
Cuyahoga kas-3-3.0.274-0.i386.rpm
http://dnl-us4.kaspersky-labs.com/products/release/english/antispam/rp m/kas-3-3.0.274-0.i386.rpm
References
Kaspersky Anti-Spam Unauthorized Directory Access Authentication Bypass Vulnerability
References:
References:
- Critical Fix 1 for Kaspersky Anti-Spam 3.0 MP1 (CF1 3.0.274.0) (Kaspersky)
- Kaspersky Home Page (Kasperksy)