NetOp School Administration Authentication Vulnerability
BID:3321
Info
NetOp School Administration Authentication Vulnerability
| Bugtraq ID: | 3321 |
| Class: | Access Validation Error |
| CVE: |
CVE-2001-1094 |
| Remote: | No |
| Local: | Yes |
| Published: | Sep 11 2001 12:00AM |
| Updated: | Jul 11 2009 07:56AM |
| Credit: | This vulnerability was posted to BugTraq by Jesse Smythe <[email protected]>. |
| Vulnerable: |
CrossTec Corp NetOp School 1.5 |
| Not Vulnerable: |
CrossTec Corp NetOp School 2.0 |
Discussion
NetOp School Administration Authentication Vulnerability
NetOp School is classroom software that allows an instructor to view, control, and broadcast to student terminals.
A malicious user can run the administrative component of the software without being challenged for any authentication.
This could allow an attacker to browse other PCs in the classroom network.
NetOp School is classroom software that allows an instructor to view, control, and broadcast to student terminals.
A malicious user can run the administrative component of the software without being challenged for any authentication.
This could allow an attacker to browse other PCs in the classroom network.
Exploit / POC
NetOp School Administration Authentication Vulnerability
There is no exploit code necessary for this vulnerability.
There is no exploit code necessary for this vulnerability.
Solution / Fix
NetOp School Administration Authentication Vulnerability
Solution:
The vendor has addressed these problems in NetOp School v2.0.
Solution:
The vendor has addressed these problems in NetOp School v2.0.
References
NetOp School Administration Authentication Vulnerability
References:
References:
- NetOp School for Windows (CrossTec Corp)