Access analysis CGI An-Analyzer released in 2019 June 24 and earlier allow remote attackers to obtain a login password via HTTP referer.
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
Link | Tags |
---|---|
https://www.anglers-net.com/anlog/update/index.html | vendor advisory |
https://jvn.jp/en/jp/JVN37230341/index.html | third party advisory |