Red-M Red-Alert 2.7.5 with software 3.1 build 24 binds authentication to IP addresses, which allows remote attackers to bypass authentication by connecting from the same IP address as an active authenticated user.
Link | Tags |
---|---|
http://www.securityfocus.com/archive/1/353211 | mailing list vendor advisory |
http://marc.info/?l=full-disclosure&m=107635119005407&w=2 | mailing list |
http://www.osvdb.org/3952 | vdb entry |
http://securitytracker.com/id?1009001 | exploit vdb entry patch vendor advisory |
http://www.securityfocus.com/bid/9618 | vdb entry vendor advisory |
http://www.securiteam.com/securitynews/5SP0C0KC0A.html | vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/15088 | vdb entry |
http://genhex.org/releases/031003.txt | vendor advisory |