Polar HelpDesk 3.0 allows remote attackers to bypass authentication by setting the UserId and UserType values in a cookie.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/16778 | vdb entry |
http://www.securityfocus.com/bid/10775 | vdb entry exploit |
http://www.osvdb.org/8168 | vdb entry |
http://www.securiteam.com/windowsntfocus/5OP0K0ADGA.html | exploit |
http://secunia.com/advisories/12120 | third party advisory vendor advisory |