Itaka before 0.2.1, when using Authentication mode, allows remote attackers to bypass authentication and obtain sensitive information by downloading screenshots via a direct request for /screenshot.
Link | Tags |
---|---|
http://www.jardinpresente.com.ar/trac/itaka/ticket/20 | patch |
http://secunia.com/advisories/26146 | patch vendor advisory third party advisory |
http://osvdb.org/38278 | vdb entry |
http://www.securityfocus.com/bid/24985 | patch vdb entry exploit |