Getahead Direct Web Remoting (DWR) before 1.1.4 allows attackers to obtain unauthorized access to public methods via a crafted request that bypasses the include/exclude checks.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Direct_web_remoting | Getahead | * | 1.1.3 (including) |
Direct_web_remoting | Getahead | 0.7 (including) | 0.7 (including) |
Direct_web_remoting | Getahead | 0.8 (including) | 0.8 (including) |
Direct_web_remoting | Getahead | 0.9 (including) | 0.9 (including) |
Direct_web_remoting | Getahead | 1.0 (including) | 1.0 (including) |
Direct_web_remoting | Getahead | 1.1.0 (including) | 1.1.0 (including) |
Direct_web_remoting | Getahead | 1.1.1 (including) | 1.1.1 (including) |
Direct_web_remoting | Getahead | 1.1.2 (including) | 1.1.2 (including) |