LG On-Screen Phone (OSP) before 4.3.010 allows remote attackers to bypass authorization via a crafted request.
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/72535 | vdb entry |
http://www.securityfocus.com/bid/72544 | vdb entry |
http://seclists.org/fulldisclosure/2015/Feb/26 | mailing list exploit |
http://packetstormsecurity.com/files/130286/LG-On-Screen-Phone-Authentication-Bypass.html | exploit |
https://exchange.xforce.ibmcloud.com/vulnerabilities/100733 | vdb entry |
http://www.securityfocus.com/archive/1/534643/100/0/threaded | mailing list |