Kerio Personal Firewall (KPF) 2.1.4 and earlier allows remote attackers to execute administrator commands by sniffing packets from a valid session and replaying them against the remote administration server.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/7179 | vdb entry |
http://marc.info/?l=bugtraq&m=105155734411836&w=2 | mailing list |
http://www.coresecurity.com/common/showdoc.php?idx=314&idxseccion=10 | exploit patch vendor advisory |
http://www.kb.cert.org/vuls/id/641012 | third party advisory us government resource |