OrbiTeam BSCW 'op' Parameter Information Disclosure Vulnerability
BID:67284
Info
OrbiTeam BSCW 'op' Parameter Information Disclosure Vulnerability
| Bugtraq ID: | 67284 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-2301 |
| Remote: | Yes |
| Local: | No |
| Published: | May 08 2014 12:00AM |
| Updated: | May 08 2014 12:00AM |
| Credit: | RedTeam Pentesting GmbH |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
OrbiTeam BSCW 'op' Parameter Information Disclosure Vulnerability
BSCW is prone to an information-disclosure vulnerability.
An attacker can exploit this issue to gain access to sensitive information; this may lead to further attacks.
BSCW prior to 5.0.8 are vulnerable.
BSCW is prone to an information-disclosure vulnerability.
An attacker can exploit this issue to gain access to sensitive information; this may lead to further attacks.
BSCW prior to 5.0.8 are vulnerable.
Exploit / POC
OrbiTeam BSCW 'op' Parameter Information Disclosure Vulnerability
Attacker can exploit this issue using web browser.
Attacker can exploit this issue using web browser.
Solution / Fix
OrbiTeam BSCW 'op' Parameter Information Disclosure Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
OrbiTeam BSCW 'op' Parameter Information Disclosure Vulnerability
References:
References: