The Change Password dialog box (change_password) in Sophos Web Appliance before 3.8.2 allows remote authenticated users to change the admin user password via a crafted request.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/66734 | vdb entry exploit |
http://www.sophos.com/en-us/support/knowledgebase/120230.aspx | vendor advisory |
http://www.zerodayinitiative.com/advisories/ZDI-14-069/ | |
http://www.exploit-db.com/exploits/32789 | exploit |
http://secunia.com/advisories/57706 | third party advisory vendor advisory |