Same-origin policy bypass vulnerabilities in several VPN product

看板Bugtraq作者時間16年前 (2009/12/03 02:01), 編輯推噓0(000)
留言0則, 0人參與, 最新討論串1/1
Vulnerabilities in several clientless SSL VPN products have been reported. Gathering authentication cookies etc. is reportedly possible. At time of writing US-CERT's advisory lists the status of about 90 vendors. US-CERT Vulnerability Note VU#261869: http://www.kb.cert.org/vuls/id/261869 Severity metric is remarkable high: 45,00. This issue is CVE-2009-2631. Juha-Matti
文章代碼(AID): #1B5gjbFb (Bugtraq)