Google Search
Exploit Archive
Web






  • Home
  • Security High Risk Plugins
  • Security Medium Risk Plugins
  • Security Low Risk Plugins
RSS Feed
Get a Free Vulnerability Scan!

SecPoint Plugin Listings

  • Home
  • Security High Risk Plugins
  • Security Medium Risk Plugins
  • Security Low Risk Plugins

SecPoint IT News

  • Instigator of TJX hacking sentenced with 20 years imprisonment
  • Conference in Europe, officiated for the battle against cybercrime
  • Google says a glitch caused the “Chinese” biography bug
  • “No ill intentions” says the Twitter hacker
  • Google promises to protect users from malicious activities
more

Axis 700 Authentication Bypass Vulnerability

Thu, 04/30/2009 - 22:19 — victor
Name: 
Allaire Spectra 1.0 Webtop Vulnerability
Filename: 
http.db
SPID: 
408
Impact: 
Allaire Spectra is a web-based e-commerce product. The Webtop portion of Spectra allows for the creation of customizable web interfaces for administration of the various services provided by the Spectra system. These interfaces can be tailored to provide separate functionality for users with different roles in the administration and deployment of the product.Due to an error in a configuration file shipped with Spectra, users who have access to only one part of the Webtop feature can gain access to all other Webtop enabled controls by typing in the exploit URL of those features. Note that to exploit this vulnerability the attacker must already have authorized access to at least one part of the Webtop interface.
Solution: 
From the advisory:1: Open the file webroot/Allaire/spectra/webtop/application.cfm2:Add the following line directly under the application initialize section:<cfset request.cfa.security.blsSecure = 1>Your code should then look this:<!---initialize the webtop ---><cfa_applicationinitializeapplicationID=088E7FE8-2AA3-11D3-AD400060B0EB2994bActiveApp=1bActiveLog=1sessionmanagement=Yessessiontimeout=30mode=design><cfset request.cfa.security.blsSecure = 1>Save the file and restart your software.If you have the ColdFusion Trusted Cache option enabled in the ColdFusion Administrator, you will need to turn it off, reload any Webtop section, then turn the Trusted Cache option on again for the change to take effect. Restarting the ColdFusion Server software will also cause the change to take affect Please upgrade to the latest stable version from http://www.allaire.com/ and click on Allaire SpectraUpdate.
Risk: 
Low

SecPoint Offers

  • Click To Buy a Protector UTM Appliance!
  • Click To Buy a Portable Penetrator Wifi Pen Test!
  • Click To Buy a Penetrator Pen Testing Appliance!
  • Click To Buy a Web Security Scan!
  • Click For a Free Security Scan!
  • Click For a Free Newsletter!

Privacy Statement | Link Policy | User Policy | SecPoint® Blog | SecPoint® Forum
SecPoint® Pictures | SecPoint® Event Pictures | SecPoint® Exploit Archive | SecPoint® Web Shop | SecPoint® Library
SecPoint® Video | SecPoint® Sitemap

© Copyright 1999-2008: SecPoint®
SecPoint ApS - Lergravsvej 53 - 2300 Copenhagen S - Phone +45 70 235 245

Recent awards Compatible with Visit us on Facebook! Visit us on LinkedIn! Visit us on Myspace!
   
Facebook
Group!




follow us on Twitter!