POSH '/portal/scr_authentif.php' Remote Information Disclosure Vulnerability
BID:65818
Info
POSH '/portal/scr_authentif.php' Remote Information Disclosure Vulnerability
| Bugtraq ID: | 65818 |
| Class: | Design Error |
| CVE: |
CVE-2014-2212 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 26 2014 12:00AM |
| Updated: | Feb 27 2014 11:21AM |
| Credit: | Anthony BAUBE, and Damien CAUQUIL |
| Vulnerable: |
Portaneo POSH 3.1.2 Portaneo POSH 3.1.1 |
| Not Vulnerable: | |
Discussion
POSH '/portal/scr_authentif.php' Remote Information Disclosure Vulnerability
POSH is prone to an information-disclosure vulnerability.
Successfully exploiting this issue may allow an attacker to obtain sensitive information that may aid in further attacks.
POSH versions 3.2.1 and prior are vulnerable.
POSH is prone to an information-disclosure vulnerability.
Successfully exploiting this issue may allow an attacker to obtain sensitive information that may aid in further attacks.
POSH versions 3.2.1 and prior are vulnerable.
Exploit / POC
POSH '/portal/scr_authentif.php' Remote Information Disclosure Vulnerability
An attacker can exploit this issue using a web browser.
An attacker can exploit this issue using a web browser.
Solution / Fix
POSH '/portal/scr_authentif.php' Remote Information Disclosure Vulnerability
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
POSH '/portal/scr_authentif.php' Remote Information Disclosure Vulnerability
References:
References:
- POSH Homepage (Portaneo)