Allegro RomPager HTTP Cookie Handling CVE-2014-9222 Security Bypass Vulnerability
BID:71744
Info
Allegro RomPager HTTP Cookie Handling CVE-2014-9222 Security Bypass Vulnerability
| Bugtraq ID: | 71744 |
| Class: | Design Error |
| CVE: |
CVE-2014-9222 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 19 2014 12:00AM |
| Updated: | Mar 19 2015 08:51AM |
| Credit: | Shahar Tal of Check Point Software Technologies |
| Vulnerable: |
Allegro RomPager 4.07 |
| Not Vulnerable: | |
Discussion
Allegro RomPager HTTP Cookie Handling CVE-2014-9222 Security Bypass Vulnerability
Allegro RomPager is prone to a security-bypass vulnerabilit.
An attacker may exploit this issue to bypass certain security restrictions and perform unauthorized actions. This may lead to further attacks.
Allegro RomPager 4.07 and prior to 4.34 are vulnerable.
Allegro RomPager is prone to a security-bypass vulnerabilit.
An attacker may exploit this issue to bypass certain security restrictions and perform unauthorized actions. This may lead to further attacks.
Allegro RomPager 4.07 and prior to 4.34 are vulnerable.
Exploit / POC
Allegro RomPager HTTP Cookie Handling CVE-2014-9222 Security Bypass Vulnerability
An attacker can exploit this issue using readily available tools.
An attacker can exploit this issue using readily available tools.