CVE Vulnerabilities

CVE-2002-0539

Published: Jul 03, 2002 | Modified: Sep 05, 2008
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

Demarc PureSecure 1.05 allows remote attackers to gain administrative privileges via a SQL injection attack in a session ID that is stored in the s_key cookie.

Affected Software

Name Vendor Start Version End Version
Puresecure Demarc_security 1.0.5_for_unix (including) 1.0.5_for_unix (including)
Puresecure Demarc_security 1.0.5_for_windows (including) 1.0.5_for_windows (including)

References