Scrutinizer Default Password Security Bypass Vulnerability
BID:54731
Info
Scrutinizer Default Password Security Bypass Vulnerability
| Bugtraq ID: | 54731 |
| Class: | Design Error |
| CVE: |
CVE-2012-3951 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 30 2012 12:00AM |
| Updated: | Aug 08 2012 07:02PM |
| Credit: | Mario Ceballos of the Metasploit Project and Jonathan Claudius of Trustwave Spiderlabs |
| Vulnerable: |
Plixer International Scrutinizer 9.0.1.19899 |
| Not Vulnerable: | |
Discussion
Scrutinizer Default Password Security Bypass Vulnerability
Scrutinizer is prone to a security-bypass vulnerability.
Successful attacks can allow an attacker to gain access to the affected application using the default authentication credentials.
Scrutinizer 9.5.0 is vulnerable; other versions may also be affected.
Scrutinizer is prone to a security-bypass vulnerability.
Successful attacks can allow an attacker to gain access to the affected application using the default authentication credentials.
Scrutinizer 9.5.0 is vulnerable; other versions may also be affected.
Exploit / POC
Scrutinizer Default Password Security Bypass Vulnerability
Attackers can use a browser to exploit these issues.
Attackers can use a browser to exploit these issues.
Solution / Fix
Scrutinizer Default Password Security Bypass Vulnerability
Solution:
Vendor updates are available. Please see the references for more information.
Solution:
Vendor updates are available. Please see the references for more information.
References
Scrutinizer Default Password Security Bypass Vulnerability
References:
References:
- Scrutinizer Homepage (Plixer International)