2E Web Option Predictable Session Token Authentication Bypass Vulnerability
BID:65537
Info
2E Web Option Predictable Session Token Authentication Bypass Vulnerability
| Bugtraq ID: | 65537 |
| Class: | Design Error |
| CVE: |
CVE-2014-1219 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 11 2014 12:00AM |
| Updated: | Feb 20 2014 12:30AM |
| Credit: | Mike Emery |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
2E Web Option Predictable Session Token Authentication Bypass Vulnerability
2E Web Option is prone to an authentication-bypass vulnerability.
An attacker can exploit this issue to bypass intended security restrictions and gain access to the affected application. Successfully exploiting this issue may lead to further attacks.
2E Web Option 8.1.2 is vulnerable; other versions may also be affected.
2E Web Option is prone to an authentication-bypass vulnerability.
An attacker can exploit this issue to bypass intended security restrictions and gain access to the affected application. Successfully exploiting this issue may lead to further attacks.
2E Web Option 8.1.2 is vulnerable; other versions may also be affected.
Exploit / POC
2E Web Option Predictable Session Token Authentication Bypass Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
2E Web Option Predictable Session Token Authentication Bypass Vulnerability
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
References
2E Web Option Predictable Session Token Authentication Bypass Vulnerability
References:
References: