Stanford WebAuth FastCGI 'login.fcgi' Information Disclosure Vulnerability
BID:59980
Info
Stanford WebAuth FastCGI 'login.fcgi' Information Disclosure Vulnerability
| Bugtraq ID: | 59980 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 15 2013 12:00AM |
| Updated: | May 15 2013 12:00AM |
| Credit: | Reported by vendor |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Stanford WebAuth FastCGI 'login.fcgi' Information Disclosure Vulnerability
Stanford WebAuth is prone to an information-disclosure vulnerability.
Successful exploits will allow attackers to obtain sensitive information that may aid in further attacks.
WebAuth versions 4.4.1 through 4.5.2 are vulnerable.
Stanford WebAuth is prone to an information-disclosure vulnerability.
Successful exploits will allow attackers to obtain sensitive information that may aid in further attacks.
WebAuth versions 4.4.1 through 4.5.2 are vulnerable.
Exploit / POC
Stanford WebAuth FastCGI 'login.fcgi' Information Disclosure Vulnerability
An attacker can exploit this issue using a web browser.
An attacker can exploit this issue using a web browser.
Solution / Fix
Stanford WebAuth FastCGI 'login.fcgi' Information Disclosure Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Stanford WebAuth FastCGI 'login.fcgi' Information Disclosure Vulnerability
References:
References: