Changes between Initial Version and Version 1 of Ticket #196
- Timestamp:
- 03/13/08 02:27:51 (17 years ago)
Legend:
- Unmodified
- Added
- Removed
- Modified
-
Ticket #196 – Description
initial v1 6 6 7 7 8 == Details ==8 == Details == 9 9 10 10 Product: Mapbender … … 21 21 22 22 23 == Introduction ==23 == Introduction == 24 24 25 25 "Mapbender is the software and portal site for geodata management of OGC … … 35 35 36 36 37 == More Details ==37 == More Details == 38 38 39 39 Due to the lack of input validation, an attacker is able to inject … … 56 56 57 57 58 == Proof of Concept ==58 == Proof of Concept == 59 59 60 60 The following request retrieves the first username and password hash … … 67 67 68 68 69 == Workaround ==69 == Workaround == 70 70 71 71 None. 72 72 73 73 74 == Fix ==74 == Fix == 75 75 76 76 The vulnerability is fixed in release 2.4.5 rc1. 77 77 78 78 79 == Security Risk ==79 == Security Risk == 80 80 81 81 As an attacker is able to e.g. get the password hashes of the … … 83 83 84 84 85 == History ==85 == History == 86 86 87 87 2007-12-14 Problem identified during a penetration test … … 92 92 93 93 94 == RedTeam Pentesting GmbH ==94 == RedTeam Pentesting GmbH == 95 95 96 96 RedTeam Pentesting is offering individual penetration tests, short