Sitepark Information Enterprise Server CVE-2014-3006 Security Bypass Vulnerability
BID:67165
Info
Sitepark Information Enterprise Server CVE-2014-3006 Security Bypass Vulnerability
| Bugtraq ID: | 67165 |
| Class: | Design Error |
| CVE: |
CVE-2014-3006 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 30 2014 12:00AM |
| Updated: | Apr 30 2014 12:00AM |
| Credit: | LSE Leading Security Experts GmbH |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Sitepark Information Enterprise Server CVE-2014-3006 Security Bypass Vulnerability
Sitepark Information Enterprise Server is prone to a security-bypass vulnerability.
An attacker may exploit this issue to bypass certain security restrictions and perform unauthorized actions.
Sitepark Information Enterprise Server 2.9 through 2.9.6 are vulnerable.
Sitepark Information Enterprise Server is prone to a security-bypass vulnerability.
An attacker may exploit this issue to bypass certain security restrictions and perform unauthorized actions.
Sitepark Information Enterprise Server 2.9 through 2.9.6 are vulnerable.
Exploit / POC
Sitepark Information Enterprise Server CVE-2014-3006 Security Bypass Vulnerability
Attackers can exploit this issue using browser or readily available tools.
Attackers can exploit this issue using browser or readily available tools.
Solution / Fix
Sitepark Information Enterprise Server CVE-2014-3006 Security Bypass Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Sitepark Information Enterprise Server CVE-2014-3006 Security Bypass Vulnerability
References:
References:
- === LSE Leading Security Experts GmbH - Security Advisory 2014-04-10 === (LSE Leading Security Experts GmbH )
- sitepark Homepage (sitepark)