McAfee IntruShield Security Management System obtains the user ID from the URL, which allows remote attackers to guess the Manager account and possibly gain privileges via a brute force attack.
Link | Tags |
---|---|
http://marc.info/?l=bugtraq&m=112076813804503&w=2 | mailing list |
http://securitytracker.com/id?1014422 | vdb entry |
http://marc.info/?l=bugtraq&m=112066594312876&w=2 | mailing list |