Tomato Module 'config.master.api.access_key' Parameter Security Weakness
BID:67350
Info
Tomato Module 'config.master.api.access_key' Parameter Security Weakness
| Bugtraq ID: | 67350 |
| Class: | Design Error |
| CVE: |
CVE-2013-7379 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 07 2013 12:00AM |
| Updated: | May 16 2014 01:02AM |
| Credit: | Adam Baldwin |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Tomato Module 'config.master.api.access_key' Parameter Security Weakness
Tomato module is prone to a security weakness.
An attacker can exploit this issue to bypass the authorization mechanism and perform actions in the context of admin user.
Tomato module prior 0.0.6 are vulnerable.
Tomato module is prone to a security weakness.
An attacker can exploit this issue to bypass the authorization mechanism and perform actions in the context of admin user.
Tomato module prior 0.0.6 are vulnerable.
Exploit / POC
Tomato Module 'config.master.api.access_key' Parameter Security Weakness
Attackers can exploit this issue using readily available tools.
Attackers can exploit this issue using readily available tools.
Solution / Fix
Tomato Module 'config.master.api.access_key' Parameter Security Weakness
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Tomato Module 'config.master.api.access_key' Parameter Security Weakness
References:
References: