sISAPILocation HTTP Header Rewrite Security Bypass Vulnerability
BID:32247
Info
sISAPILocation HTTP Header Rewrite Security Bypass Vulnerability
| Bugtraq ID: | 32247 |
| Class: | Unknown |
| CVE: |
CVE-2008-6298 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 10 2008 12:00AM |
| Updated: | May 07 2015 05:21PM |
| Credit: | JVN |
| Vulnerable: |
sISAPILocation sISAPILocation 1.0.2 .1 |
| Not Vulnerable: |
sISAPILocation sISAPILocation 1.0.2 .2 |
Discussion
sISAPILocation HTTP Header Rewrite Security Bypass Vulnerability
sISAPILocation is prone to a security-bypass vulnerability.
Attackers can exploit this issue to bypass certain configuration settings such as character encoding and the secure flag for cookies.
sISAPILocation 1.0.2.1 and prior versions are affected.
sISAPILocation is prone to a security-bypass vulnerability.
Attackers can exploit this issue to bypass certain configuration settings such as character encoding and the secure flag for cookies.
sISAPILocation 1.0.2.1 and prior versions are affected.
Exploit / POC
sISAPILocation HTTP Header Rewrite Security Bypass Vulnerability
Attackers can exploit this issue through a browser.
Attackers can exploit this issue through a browser.
Solution / Fix
sISAPILocation HTTP Header Rewrite Security Bypass Vulnerability
Solution:
The vendor has released an update. Please see the references for more information.
Solution:
The vendor has released an update. Please see the references for more information.
References
sISAPILocation HTTP Header Rewrite Security Bypass Vulnerability
References:
References: