AIDA Web Frame.HTML Multiple Unauthorized Access Vulnerabilities
BID:26464
Info
AIDA Web Frame.HTML Multiple Unauthorized Access Vulnerabilities
| Bugtraq ID: | 26464 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-6056 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 14 2007 12:00AM |
| Updated: | Dec 18 2007 08:05PM |
| Credit: | MC Iglo discovered these issues. |
| Vulnerable: |
AIDA ORGA AIDA Web 0 |
| Not Vulnerable: | |
Discussion
AIDA Web Frame.HTML Multiple Unauthorized Access Vulnerabilities
AIDA Web is prone to multiple unauthorized access vulnerabilities.
An attacker could exploit these issues to obtain potentially sensitive information that could aid in further attacks.
AIDA Web is prone to multiple unauthorized access vulnerabilities.
An attacker could exploit these issues to obtain potentially sensitive information that could aid in further attacks.
Exploit / POC
AIDA Web Frame.HTML Multiple Unauthorized Access Vulnerabilities
Attackers can use a browser to exploit these issues.
The following proof-of-concept URIs are available:
http://www.example.com/CGI-Bin/frame.html?Mehr=xxx
http://www.example.com/CGI-Bin/frame.html?Mehr=xxx&SUPER=x
Attackers can use a browser to exploit these issues.
The following proof-of-concept URIs are available:
http://www.example.com/CGI-Bin/frame.html?Mehr=xxx
http://www.example.com/CGI-Bin/frame.html?Mehr=xxx&SUPER=x
Solution / Fix
AIDA Web Frame.HTML Multiple Unauthorized Access Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for these issues. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for these issues. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
AIDA Web Frame.HTML Multiple Unauthorized Access Vulnerabilities
References:
References:
- Vendor Homepage (AIDA ORGA)
- Aida-Web Information Exposure ("MC Iglo"
)