Netegrity SiteMinder before 4.11 allows remote attackers to bypass its authentication mechanism by appending "$/FILENAME.ext" (where ext is .ccc, .class, or .jpg) to the requested URL.
Link | Tags |
---|---|
http://www.atstake.com/research/advisories/2000/a091100-1.txt | vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/5230 | vdb entry |
http://www.securityfocus.com/bid/1681 | vdb entry patch vendor advisory |