The web administrative portal in Zhone zNID 2426A before S3.0.501 allows remote authenticated users to bypass intended access restrictions via a modified server response, related to an insecure direct object reference.
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
Link | Tags |
---|---|
http://packetstormsecurity.com/files/133921/Zhone-Insecure-Reference-Password-Disclosure-Command-Injection.html | exploit vdb entry third party advisory |
https://www.exploit-db.com/exploits/38453/ | exploit vdb entry third party advisory |
http://seclists.org/fulldisclosure/2015/Oct/57 | mailing list exploit third party advisory |