Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- > [Suggested description]
- > An access control issue in Makves DCAP v3.0.0.183 allows
- > unauthenticated attackers to obtain cleartext credentials via a crafted
- > web request to the product API.
- >
- > ------------------------------------------
- >
- > [Vulnerability Type]
- > Incorrect Access Control
- >
- > ------------------------------------------
- >
- > [Vendor of Product]
- > Makves
- >
- > ------------------------------------------
- >
- > [Affected Product Code Base]
- > DCAP - 3.0.0.183
- >
- > ------------------------------------------
- >
- > [Attack Type]
- > Remote
- >
- > ------------------------------------------
- >
- > [Impact Information Disclosure]
- > true
- >
- > ------------------------------------------
- >
- > [Attack Vectors]
- > Sensitive information is accessible via web request without authorization.
- >
- > ------------------------------------------
- >
- > [Discoverer]
- > Ilya Kostyulin
- >
- > ------------------------------------------
- >
- > [Reference]
- > http://makves.ru
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement