Advertisement
Guest User

Untitled

a guest
Jun 20th, 2023
2,549
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.96 KB | Cybersecurity | 0 0
  1. > [Suggested description]
  2. > An access control issue in Makves DCAP v3.0.0.183 allows
  3. > unauthenticated attackers to obtain cleartext credentials via a crafted
  4. > web request to the product API.
  5. >
  6. > ------------------------------------------
  7. >
  8. > [Vulnerability Type]
  9. > Incorrect Access Control
  10. >
  11. > ------------------------------------------
  12. >
  13. > [Vendor of Product]
  14. > Makves
  15. >
  16. > ------------------------------------------
  17. >
  18. > [Affected Product Code Base]
  19. > DCAP - 3.0.0.183
  20. >
  21. > ------------------------------------------
  22. >
  23. > [Attack Type]
  24. > Remote
  25. >
  26. > ------------------------------------------
  27. >
  28. > [Impact Information Disclosure]
  29. > true
  30. >
  31. > ------------------------------------------
  32. >
  33. > [Attack Vectors]
  34. > Sensitive information is accessible via web request without authorization.
  35. >
  36. > ------------------------------------------
  37. >
  38. > [Discoverer]
  39. > Ilya Kostyulin
  40. >
  41. > ------------------------------------------
  42. >
  43. > [Reference]
  44. > http://makves.ru
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement