Ceondo InDefero Unauthorized Access Vulnerability
BID:38425
Info
Ceondo InDefero Unauthorized Access Vulnerability
| Bugtraq ID: | 38425 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 25 2010 12:00AM |
| Updated: | Feb 25 2010 12:00AM |
| Credit: | Anonymous |
| Vulnerable: |
Ceondo Indefero 0.8.9 |
| Not Vulnerable: |
Ceondo Indefero 0.8.10 |
Discussion
Ceondo InDefero Unauthorized Access Vulnerability
InDefero is prone to an unauthorized-access vulnerability because it fails to adequately restrict access to potentially sensitive information.
An attacker can exploit this vulnerability to gain unauthorized access to other users' projects; other attacks may be possible.
Versions prior to InDefero 0.8.10 are vulnerable; other versions may also be affected.
InDefero is prone to an unauthorized-access vulnerability because it fails to adequately restrict access to potentially sensitive information.
An attacker can exploit this vulnerability to gain unauthorized access to other users' projects; other attacks may be possible.
Versions prior to InDefero 0.8.10 are vulnerable; other versions may also be affected.
Exploit / POC
Ceondo InDefero Unauthorized Access Vulnerability
Attackers may launch attacks through a browser.
Attackers may launch attacks through a browser.
Solution / Fix
Ceondo InDefero Unauthorized Access Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Ceondo InDefero Unauthorized Access Vulnerability
References:
References:
- Ceondo Indefero Security Vulnerability (Ceondo)
- InDefero Homepage (Ceondo)